Impact
The vulnerability is a subscriber-level SQL injection in the Tainacan WordPress plugin. By manipulating input that is not properly sanitized, an attacker can craft malicious SQL statements that are executed against the site database. This allows the attacker to read, modify, or delete data, potentially leading to loss of confidentiality, integrity, and availability of the application. The weakness is identified as CWE-89.
Affected Systems
The flaw exists in all Tainacan WordPress plugin releases up to and including version 1.2.0. All WordPress sites that host the Tainacan plugin and have any user role that can supply subscriber input are susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as high severity. While the EPSS score is not available, the lack of a KEV listing suggests that wide-scale exploitation is not documented yet, but the potential impact remains significant. The likely attack vector involves unsanitized subscriber input that is reflected in SQL queries; an attacker with adequate access or the ability to inject input can exploit the flaw to run arbitrary SQL commands.
OpenCVE Enrichment