HomeDefault status
unaffected
Any version before 3.0.9
affected
Description
The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Problem types
Product status
Any version before 3.0.9
Credits
Bob Matyas
WPScan
References
wpscan.com/...rability/390baaf8-a162-43e5-9367-0d2e979d89f7/
wpscan.com/...rability/390baaf8-a162-43e5-9367-0d2e979d89f7/