Security Advisory

CVE-2024-9828

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-11-21 06:00:10
Last updated 2026-01-09 20:36:07
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks