cleantalk
Vulnerabilities and Security Researches

Taskbuilder – WordPress Project & Task Management plugin, CVE-2024-9828

CVE, Research URL

CVE-2024-9828

Published on
Nov 21, 2024
Research Description
The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks
Affected versions
Min -, max 3.0.5.
Status
vulnerable