Impact
The Taskbuilder WordPress plugin up to version 6.0.5 contains a blind SQL injection flaw caused by improper neutralization of special elements in SQL commands. This weakness can allow an attacker to query the database without direct feedback, potentially revealing or altering data. The vulnerability is classified under CWE‑89.
Affected Systems
Any WordPress site that has installed the Taskbuilder plugin with a version ranging from its initial release through 6.0.5 is affected. The flaw is present in all plugin installs within this version range, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers can potentially exploit the vulnerability by sending crafted HTTP requests to the plugin’s taskbuilder interface, assuming the site is reachable from the internet. This inferred remote attack vector highlights the need for swift remediation.
OpenCVE Enrichment