nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-42740 CVE-2026-42740
CRITICAL
WordPress Tainacan plugin <= 1.0.3 - SQL Injection vulnerability
Record summary
CVE-2026-42740 has a selected CVSS score of 9.3 (critical).
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TainacanBrowse tainacan / TainacanDefault status: unaffected | CVE List | Through 1.0.3 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/Wordpress/Plugin/tainacan/vulnerability/wordpress-tainacan-plugin-1-0-3-sql-injection-vulnerability?_s_id=cve