Unauthorized Metadata Creation in Tainacan Plugin for WordPress
CVE-2025-14043

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
21 December 2025

What is CVE-2025-14043?

The Tainacan plugin for WordPress contains a vulnerability that allows unauthorized users to create metadata sections due to inadequate authorization checks in its implementation. Specifically, the create_item_permissions_check() function lacks the necessary authentication and authorization validation, which allows attackers without valid credentials to exploit the public REST API and generate arbitrary metadata sections for collections. This oversight poses significant risks to the integrity of the data within the WordPress site.

Affected Version(s)

Tainacan * <= 1.0.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deadbee
.
CVE-2025-14043 : Unauthorized Metadata Creation in Tainacan Plugin for WordPress