← volver
CVE-2025-12747

Tainacan <= 1.0.0 - Unauthenticated Information Exposure

CVSS 5.3 MEDIUMEPSS 0.3%CWE-552
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
21 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files that have been marked as private.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
tainacan · Tainacan

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →