plugin

Task Manager Vulnerabilities

4 known security issues reported for the Task Manager WordPress plugin. Most recent disclosed Mar 24, 2026.

1 high 3 medium

Running Task Manager on your site? Check whether your installed version is affected.

Scan your site free

Task Manager - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Parameter vulnerability

medium

Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Parameter vulnerability

CVSS:
6.5
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Mar 24, 2026

Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Read

medium

The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which c...

CVSS:
6.5
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-2351 on NVD →

Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Parameter

medium

The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode syntax (square brackets) to pa...

CVSS:
6.5
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-4004 on NVD →

Task Manager <= 3.0.2 - Unauthenticated Local File Inclusion

high

The Task Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access control...

CVSS:
8.1
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Aug 29, 2025

CVE-2025-60078 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database