Tainá
Tainá has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Tainá has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Tainá is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-26919Tainá <= 0.2.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Tainá
Author
tainacan
A full-site-editing block theme for WordPress. Tainá has emerged as a new alternative for viewing cultural digital archives created with WordPress and its amazing tools such as the Tainacan plugin. In addition to a fully customizable interface, this theme brings support for several design patterns available for insertion in a single click, such as banners ready to introduce your content, whether it has one, two or no image to be represented by. You can also change the global styles of your website to make it match your visual identity in a single click, including beautiful dark theme variations. Tainá theme brings your audience the ability to easily, quickly and intuitively access your collection files by creating a unique viewing experience for your digital repository.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C