Taskbuilder – WordPress Project & Task Management plugin, CVE-2024-9828
- CVE, Research URL
- Home page URL
-
Security reports for Taskbuilder – WordPress Project & Task Management plugin
- Published on
- Nov 21, 2024
- Research Description
- The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks
- Affected versions
-
Min -, max 3.0.5.
- Status
-
vulnerable