CVE-2025-12747
Last modified
CVE-2025-12747 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files that have been marked as private.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files that have been marked as private.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12747?
How severe is CVE-2025-12747?
How do I fix CVE-2025-12747?
Are you affected by CVE-2025-12747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
