Executive brief
The Taskbuilder plugin for WordPress, used for project and task management, contains a security flaw that could allow logged-in users to access sensitive information from the website's database. By exploiting this vulnerability, an attacker with basic account access (such as a subscriber) could run unauthorized database queries. This could lead to the exposure of confidential business data, user credentials, or other private information stored on the site.
Technical details
The Taskbuilder plugin for WordPress is vulnerable to time-based blind SQL injection due to insufficient escaping of the 'project_search' parameter and a lack of SQL query preparation. This vulnerability exists in all versions up to and including 5.0.6. An authenticated attacker with Subscriber-level permissions or higher can exploit this by sending crafted network requests to append malicious SQL commands to existing queries. Successful exploitation allows the attacker to exfiltrate sensitive data from the database based on the time delay of the server's response. A patch appears to be available in the plugin's changeset 3507782.
Affected products
- The Taskbuilder Taskbuilder – Project Management & Task Management Tool With Kanban Board Up to and including 5.0.6
Timeline
- 2026-05-14: disclosed: Vulnerability published on NVD and Wordfence