CVE-2024-9831: Taskbuilder < 3.0.9 - Admin+ SQL Injection
Published May 15, 2025
·Updated
The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
Taskbuilder Taskbuilder<3.0.9
Taskbuilder Taskbuilder WordPress<3.0.9
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-9831?
CVE-2024-9831 has a high severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-9831?
To fix CVE-2024-9831, update the Taskbuilder plugin to version 3.0.9 or later.
3
What versions of the Taskbuilder plugin are affected by CVE-2024-9831?
CVE-2024-9831 affects versions of the Taskbuilder plugin prior to 3.0.9.
4
Who is at risk from CVE-2024-9831?
Admins using Taskbuilder versions before 3.0.9 are at risk of SQL injection attacks due to this vulnerability.
5
What type of vulnerability is CVE-2024-9831?
CVE-2024-9831 is classified as a SQL injection vulnerability.