CVE-2025-26919: WordPress Tainá plugin <= 0.2.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá allows Stored XSS. This issue affects Tainá: from n/a through 0.2.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá taina allows Stored XSS.This issue affects Tainá: from n/a through < 0.2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26919?
CVE-2025-26919 is classified as a critical severity vulnerability due to its potential to allow stored Cross-site Scripting (XSS) attacks.
What impact does CVE-2025-26919 have on affected systems?
CVE-2025-26919 can lead to unauthorized access and manipulation of user data, as it allows attackers to inject malicious scripts into web pages.
How can I fix CVE-2025-26919?
To fix CVE-2025-26919, upgrade Tainá or the Tainá WordPress plugin to version 0.2.3 or later, which addresses the vulnerability.
What versions are affected by CVE-2025-26919?
CVE-2025-26919 affects Tainá versions up to and including 0.2.2.
Who is impacted by CVE-2025-26919?
Users and administrators utilizing Tainá or the Tainá WordPress plugin prior to version 0.2.3 are at risk due to CVE-2025-26919.