Security Advisory

CVE-2024-9828

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-11-21 06:00:10
Last updated 2026-01-09 20:36:07
Assigner WPScan
State PUBLISHED

Description

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the load_orders parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks