SQL Injection Vulnerability in Taskbuilder Project Management Tool by WordPress
CVE-2026-15267
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15267?
The Taskbuilder plugin for WordPress is susceptible to SQL Injection through the 'wppm_proj_filter' parameter, mainly affecting versions up to and including 5.0.9. This flaw arises from inadequate escaping of user inputs and the mishandling of the SQL query preparation. Specifically, the problematic code allows an authenticated user with a subscriber-level role or higher to inject malicious SQL code into the database. The input is improperly concatenated into the SQL WHERE clause without appropriate sanitization or parameterization, leading to a risk of sensitive data exposure. Users are advised to upgrade to a patched version immediately to mitigate this risk.
Affected Version(s)
Taskbuilder β Project Management & Task Management Tool With Kanban Board 0 <= 5.0.9