SQL Injection Vulnerability in Tainacan Plugin for WordPress
CVE-2026-95590

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-95590?

The Tainacan plugin for WordPress is vulnerable to SQL Injection, affecting all versions up to and including 1.2.0. This vulnerability allows unauthorized users to manipulate database queries, potentially leading to data exposure, unauthorized access, or even complete site compromise. Website owners using the affected versions should immediately apply patches or update their installations to protect against potential exploitation.

Affected Version(s)

Tainacan <= 1.2.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program
.