Junglewise Threat Intelligence

CVE-2026-42740: Tainacan SQL injection in WordPress plugin

CVE-2026-42740 · Severity: critical · CVSS 9.3 · Published 2026-05-27

Executive brief

Tainacan, a digital repository platform for WordPress, contains a security flaw that could allow an attacker to interfere with its database. By exploiting this vulnerability, an unauthorized individual could potentially steal sensitive information, modify data, or disrupt the service entirely. This poses a significant risk to the integrity and confidentiality of the digital collections managed by the software.

Technical details

A Blind SQL Injection vulnerability exists in the Tainacan plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send crafted requests to the application and infer data from the database based on the server's response patterns. This can lead to full database compromise, including the extraction of sensitive user credentials or administrative session tokens. The vulnerability is present in versions up to 1.0.3; users are advised to check for updates from the vendor.

Affected products

  • Tainacan Tainacan <= 1.0.3

Timeline

  • 2026-05-27: advisory: Vulnerability published by NVD

References

Related threats