CVE-2025-12747
BaseFortify
Publication date: 2025-11-21
Last updated on: 2025-11-21
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tainacan | plugin | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Tainacan plugin for WordPress has a vulnerability where files uploaded and marked as private are exposed in the wp-content directory without proper protection. This allows unauthenticated attackers to access and extract potentially sensitive information from these supposedly private files.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized disclosure of sensitive information stored in files marked as private within the Tainacan plugin. An attacker without authentication can access these files, potentially compromising confidentiality and privacy of the data.