SQL Injection Vulnerability in Taskbuilder Project Management Tool by WordPress
CVE-2026-15267

6.5MEDIUM

What is CVE-2026-15267?

The Taskbuilder plugin for WordPress is susceptible to SQL Injection through the 'wppm_proj_filter' parameter, mainly affecting versions up to and including 5.0.9. This flaw arises from inadequate escaping of user inputs and the mishandling of the SQL query preparation. Specifically, the problematic code allows an authenticated user with a subscriber-level role or higher to inject malicious SQL code into the database. The input is improperly concatenated into the SQL WHERE clause without appropriate sanitization or parameterization, leading to a risk of sensitive data exposure. Users are advised to upgrade to a patched version immediately to mitigate this risk.

Affected Version(s)

Taskbuilder – Project Management & Task Management Tool With Kanban Board 0 <= 5.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NOn Nss
.