Junglewise Threat Intelligence

CVE-2026-12090: Taskbuilder WordPress plugin SQL injection in wppm_proj_filter

CVE-2026-12090 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Executive brief

The Taskbuilder plugin for WordPress, which provides project management and Kanban board features, contains a security flaw that allows logged-in users to access sensitive database information. By sending specially crafted requests, an attacker with even basic account access (such as a subscriber) can bypass security measures to view data they are not authorized to see. This could lead to the exposure of confidential project details or user information stored in the website's database.

Technical details

A SQL injection vulnerability exists in the Taskbuilder WordPress plugin due to insufficient escaping of the 'wppm_proj_filter' parameter and a lack of SQL query preparation in the wp_ajax_wppm_view_project_tasks handler. The vulnerability is accessible to any authenticated user, including those with low-level 'subscriber' privileges, because the affected AJAX handler lacks nonce verification. An attacker can exploit this by appending malicious SQL commands to existing queries to perform unauthorized data extraction. The issue is addressed in version 5.0.9.

Affected products

  • taskbuilder Taskbuilder – Project Management & Task Management Tool With Kanban Board up to, and including, 5.0.8

Timeline

  • 2026-07-01: disclosed: CVE published to NVD dataset
  • 2026-07-01: advisory

References