Impact
The Taskbuilder plugin contains a missing authorization check that allows an attacker to invoke functions that should be protected by access control lists. This flaw permits the execution of privileged plugin operations without proper authentication or permission verification, which could lead to unauthorized data manipulation or other unintended actions. The weakness corresponds to CWE‑862 (Missing Authorization) and is explicitly described as "Missing Authorization vulnerability ... allows Accessing Functionality Not Properly Constrained by ACLs."
Affected Systems
WordPress installations that have the Taskbuilder plugin deployed with version 4.0.7 or earlier are affected. The CNA product identifier is taskbuilder:Taskbuilder, and the affected range includes all releases up to and including 4.0.7.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1 percent suggests a very low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog, implying no confirmed exploits in the wild. The likely attack vector is via HTTP requests to plugin endpoints that are exposed through the WordPress web interface; based on the description, it is inferred that an unauthenticated attacker could craft requests to the vulnerable functions, bypassing any intended access restrictions.
OpenCVE Enrichment
EUVD