Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the WordPress Tainacan plugin to the latest available version (at least 1.4.0).
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0. | |
| Title | WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-10T14:00:12.587Z
Reserved: 2026-09-22T00:19:50.791Z
Link: CVE-2026-94676
No data.
Status : Received
Published: 2026-10-10T14:16:38.130
Modified: 2026-10-10T14:16:38.130
Link: CVE-2026-94676
No data.
OpenCVE Enrichment
Updated: 2026-10-10T16:00:08Z
Weaknesses