Junglewise Threat Intelligence

CVE-2026-52697: Taskbuilder WordPress plugin SQL injection

CVE-2026-52697 · Severity: high · CVSS 8.5 · Published 2026-06-15

Executive brief

Taskbuilder is a WordPress plugin used for managing tasks and projects. A security flaw allows logged-in users with basic 'Subscriber' permissions to execute unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of site configuration details, or disruption of website operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Taskbuilder plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is accessible to authenticated users with 'Subscriber' level privileges, which is the default low-level role for many WordPress sites. By sending specially crafted network requests, an attacker can bypass security controls to execute arbitrary SQL queries against the backend database. This can result in full data exfiltration or limited service disruption. The issue is resolved in version 5.0.8.

Affected products

  • Taskbuilder Taskbuilder <= 5.0.7

Timeline

  • 2026-05-16: other: Reported by researcher VanTastic
  • 2026-06-10: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References