← WordPress Vulnerabilities
WordPress security by component

Taskbuilder

Taskbuilder is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 8.5.

Plugin slug: taskbuilder

CVE-2026-15267: Taskbuilder subscribers can inject SQL through project filtering

Taskbuilder through 5.0.9 exposes the authenticated wppm_view_project_tasks AJAX action without a capability check beyond having a WordPress account. The request's wppm_proj_filter value can be re-read with only sanitize_text_field(), concatenated as an unquoted operand into Task.project, and embedded in the query instead of being passed as a $wpdb->prepare() argument. A Subscriber can therefore alter the query and extract sensitive database information. The CNA record does not identify the precise database contents obtainable. Version 6.0.0 casts the value with absint() and binds it with a %d placeholder.

PublishedJul 28, 2026
Known safe version6.0.0
Safe version
Jul 28, 2026 CVE-2026-15267
Taskbuilder subscribers can inject SQL through project filtering
Taskbuilder through 5.0.9 exposes the authenticated wppm_view_project_tasks AJAX action without a capability check beyond having a WordPress account. The request's wppm_proj_filter value can be re-read with only sanitize_text_field(), concatenated as an unquoted operand into Task.project, and embedded in the query instead of being passed as a $wpdb->prepare() argument. A Subscriber can therefore alter the query and extract sensitive database information. The CNA record does not identify the precise database contents obtainable. Version 6.0.0 casts the value with absint() and binds it with a %d placeholder.
6.0.0
CVE6.5
NVDPending
Jul 01, 2026 CVE-2026-12110
Taskbuilder – Project Management & Task Management Tool With Kanban Board: SQL injection
Taskbuilder – Project Management & Task Management Tool With Kanban Board is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.8.
> 5.0.8
CVE6.5
NVDPending
Jul 01, 2026 CVE-2026-12090
Taskbuilder – Project Management & Task Management Tool With Kanban Board: SQL injection
Taskbuilder – Project Management & Task Management Tool With Kanban Board is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.8.
> 5.0.8
CVE6.5
NVDPending
Jun 17, 2026 CVE-2026-9570
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 5.0.8.
5.0.8
CVE7.1
NVDPending
Jun 15, 2026 CVE-2026-52697
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 5.0.7.
5.0.8
CVE8.5
NVDPending
Mar 04, 2026 CVE-2026-2289
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending
Feb 18, 2026 CVE-2026-1640
Taskbuilder – WordPress Project Management & Task Management: A security weakness
Taskbuilder – WordPress Project Management & Task Management is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1639
Taskbuilder – WordPress Project Management & Task Management: SQL injection
Taskbuilder – WordPress Project Management & Task Management is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Jan 08, 2026 CVE-2025-67933
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 06, 2025 CVE-2025-30945
Taskbuilder: A security weakness
Taskbuilder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 15, 2025 CVE-2024-9831
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Apr 17, 2025 CVE-2025-39569
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Jan 21, 2025 CVE-2025-22716
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD8.8
Jan 04, 2025 CVE-2024-11930
Taskbuilder – WordPress Project & Task Management plugin: Cross-site scripting
Taskbuilder – WordPress Project & Task Management plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 21, 2024 CVE-2024-9828
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.1
NVDPending
Oct 10, 2022 CVE-2022-3137
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4