CVE-2025-12747

Source
https://cve.org/CVERecord?id=CVE-2025-12747
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12747.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12747
Published
2025-11-21T16:28:14.277Z
Modified
2026-08-12T03:51:45.934119092Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Tainacan <= 1.0.0 - Unauthenticated Information Exposure
Details

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files that have been marked as private.

Database specific
{
    "cwe_ids": [
        "CWE-552"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12747.json",
    "cna_assigner": "Wordfence"
}
References

Affected packages

Git / github.com/tainacan/tainacan

Affected ranges

Type
GIT
Repo
https://github.com/tainacan/tainacan
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1
0.11
0.12
0.13
0.13.1
0.14
0.14.1
0.14.2
0.15
0.15.2
0.16
0.16.1
0.16.2
0.16.3
0.17
0.17.1
0.17.2
0.17.3
0.17.4
0.18
0.18.1
0.18.10
0.18.2
0.18.3
0.18.4
0.18.5
0.18.6
0.18.7
0.18.8
0.18.9
0.19
0.19.1
0.19.2
0.19.3
0.20.0
0.20.1
0.20.2
0.20.3
0.20.4
0.20.5
0.20.6
0.20.7
0.20.8
0.21.0
0.21.1
0.21.10
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.3
0.7
1.*
1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12747.json"