


Perceptive Security
SOC/SIEM Consultancy

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to …
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 13:00:51
Source:
nvd.nist.gov
Web Technologies, Database & Storage
The Tainacan plugin for WordPress is affected by a time-based blind SQL injection vulnerability via the 'geoquery' parameter in all versions up to and including 1.0.3. The flaw stems from insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries. Unauthenticated attackers can exploit this vulnerability to append malicious SQL queries and extract sensitive information from the database. No authentication is required to exploit this issue, significantly raising its risk level. A fix has been committed to the GitHub repository. The vulnerability is tracked as CVE-2026-6230 and has been documented by both NVD and Wordfence.
Technical details
Mitigation steps:
Affected products:
Tainacan WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6230
https://github.com/tainacan/tainacan/commit/579d28d7752b27ed3407f5197abb6349b3efc3c9
https://www.wordfence.com/threat-intel/vulnerabilities/id/241d9cd3-9331-49b2-8083-dc646070488e?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
