Time-based Blind SQL Injection in Taskbuilder Project Management Plugin for WordPress
CVE-2026-1639
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2026
What is CVE-2026-1639?
The Taskbuilder plugin for WordPress is vulnerable to a time-based blind SQL injection due to inadequate input sanitization on the 'order' and 'sort_by' parameters. This flaw allows authenticated attackers with at least subscriber-level access to manipulate SQL queries, potentially enabling them to extract sensitive data from the database. Effective mitigation strategies should be implemented to safeguard against unauthorized data access.
Affected Version(s)
Taskbuilder – Project Management & Task Management Tool With Kanban Board 0 <= 5.0.2