top of page
perceptive_background_267k.jpg

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to …

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 13:00:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

The Tainacan plugin for WordPress is affected by a time-based blind SQL injection vulnerability via the 'geoquery' parameter in all versions up to and including 1.0.3. The flaw stems from insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries. Unauthenticated attackers can exploit this vulnerability to append malicious SQL queries and extract sensitive information from the database. No authentication is required to exploit this issue, significantly raising its risk level. A fix has been committed to the GitHub repository. The vulnerability is tracked as CVE-2026-6230 and has been documented by both NVD and Wordfence.

Technical details

Mitigation steps:

Affected products:

Tainacan WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page