SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15267

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Taskbuilder plugin for WordPress is vulnerable to SQL Injection through the 'wppm_proj_filter' parameter, allowing authenticated attackers with subscriber-level access or higher to manipulate SQL queries and potentially extract sensitive database information. This vulnerability arises from improper handling of user-supplied input, which fails to adequately escape and parameterize SQL queries. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-15267
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
WordPress

Original NVD Description

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query — the value is re-read at line 144 using only sanitize_text_field() (overwriting the earlier absint() result), then concatenated into the SQL WHERE clause as an unquoted numeric operand using only esc_sql(), which does not protect against injection in that context, and finally string-interpolated into the $wpdb->prepare() format string, bypassing parameterization entirely. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.