Unauthorized Metadata Creation in Tainacan Plugin for WordPress
CVE-2025-14043
What is CVE-2025-14043?
The Tainacan plugin for WordPress contains a vulnerability that allows unauthorized users to create metadata sections due to inadequate authorization checks in its implementation. Specifically, the create_item_permissions_check() function lacks the necessary authentication and authorization validation, which allows attackers without valid credentials to exploit the public REST API and generate arbitrary metadata sections for collections. This oversight poses significant risks to the integrity of the data within the WordPress site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tainacan * <= 1.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved