Executive brief
The Taskbuilder plugin for WordPress, used for project and task management, contains a security flaw that allows logged-in users with basic permissions to access sensitive database information. By sending specially crafted requests, an attacker could bypass security filters to view data they are not authorized to see. This could lead to the exposure of confidential project details or user information stored in the website's database.
Technical details
A SQL injection vulnerability exists in the Taskbuilder WordPress plugin due to improper handling of the 'wppm_proj_filter' parameter. The vulnerability occurs because the code overwrites a safe integer conversion with a less secure text sanitization function, then concatenates the result into a SQL WHERE clause as an unquoted numeric operand. Furthermore, the value is string-interpolated into a format string before being passed to $wpdb->prepare(), effectively bypassing parameterization. Authenticated attackers with subscriber-level access or higher can exploit this to append arbitrary SQL queries and extract sensitive data from the database. The issue is addressed in versions following 5.0.9.
Affected products
- Taskbuilder Taskbuilder – Project Management & Task Management Tool With Kanban Board up to, and including, 5.0.9
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
References
- https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/admin/projects/open_project/wppm_view_project_tasks.php
- https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/admin/projects/open_project/wppm_view_project_tasks.php
- https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/class-wppm-admin.php
- https://plugins.trac.wordpress.org/changeset/3576941/taskbuilder/trunk/includes/admin/projects/open_project/wppm_view_project_tasks.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/746eec41-e8d2-4c51-b63e-726eeadbb2ab?source=cve