cleantalk
Vulnerabilities and Security Researches

Taskbuilder – WordPress Project & Task Management plugin, CVE-2022-3137

CVE, Research URL

CVE-2022-3137

Published on
Oct 11, 2022
Research Description
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
Affected versions
Min -, max 1.0.8.
Status
vulnerable