Impact
The Tainacan plugin for WordPress is vulnerable to a time‑based blind SQL injection through the 'geoquery' REST statements by concatenating the user‑supplied input without proper escaping or parameterization, allowing an unauthenticated attacker to append and execute arbitrary SQL commands on the underlying database. This is a CWE-89 vulnerability.
Affected Systems
WordPress sites that have installed the Tainacan plugin version 1.0.3 or earlier are affected. The flaw exists in all releases up to and including 1.0.3, regardless of the WordPress core version. Upgrading to a newer Tainacan release removes the vulnerable 'geoquery' handler.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on confidentiality in the absence of authentication. The EPSS score of < 1% suggests a low probability of exploitation in the wild, but the publicly accessible endpoint and lack of authentication make exploitation straightforward. Although the vulnerability is not listed in the CISA KEV catalog, the potential for database compromise warrants immediate attention.
OpenCVE Enrichment