Impact
An SQL Injection flaw exists in the Taskbuilder plugin for WordPress because special characters in SQL statements are not properly sanitized. A successful exploit would let an attacker inject and execute arbitrary SQL commands against the site’s database, allowing unauthorized read, modify or delete operations on records such as user credentials, posts and configuration data, ultimately compromising the entire site.
Affected Systems
WordPress installations that have the Taskbuilder plugin version 3.0.6 or earlier are vulnerable. No specific WordPress core version restrictions are mentioned, so any site running a vulnerable plugin version is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity while the EPSS score of less than 1% suggests a relatively low likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Likely attack vector is remote HTTP requests sent to the plugin’s input fields or endpoints, as the flaw is a web‑accessible SQL injection. The plugin must be enabled and the web server reachable for exploitation. If successful, the attacker could compromise confidentiality and integrity of the database.
OpenCVE Enrichment
EUVD