CVE-2025-22716: high-severity vulnerability in Taskbuilder
WordPress Taskbuilder Plugin <= 3.0.6 - SQL Injection vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows SQL Injection.This issue affects Taskbuilder: from n/a through <= 3.0.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Affected products
taskbuilder · TaskbuilderRelated CVEs — Taskbuilder
In the same product, most dangerous first.
CVE-2025-39569HIGHWordPress Taskbuilder plugin <= 4.0.1 - SQL Injection VulnerabilityEPSS 0.3%CVE-2025-30945MEDIUMWordPress Taskbuilder plugin <= 4.0.7 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-67933HIGHWordPress Taskbuilder plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%