CyberRota
← Ana sayfaya dön

CVE-2026-15267

MEDIUM · CVSS 6.5 EPSS %0.26

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-28T09:16:42.107 · Çekilme zamanı: 2026-07-28T18:30:38.063182+00:00

CyberRota Yorumu

SQL Injection riski içeriyor.

CVE
CVE-2026-15267
Severity
MEDIUM
CVSS
6.5
EPSS
%0.26
WordPress

Orijinal NVD Açıklaması

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query — the value is re-read at line 144 using only sanitize_text_field() (overwriting the earlier absint() result), then concatenated into the SQL WHERE clause as an unquoted numeric operand using only esc_sql(), which does not protect against injection in that context, and finally string-interpolated into the $wpdb->prepare() format string, bypassing parameterization entirely. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.