CVE-2026-4004: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4004 is an arbitrary shortcode execution vulnerability in the Task Manager plugin for WordPress, affecting all versions up to and including 3.0.2. The flaw stems from missing capability checks in the callback_search() function combined with insufficient input validation, allowing authenticated attackers with Subscriber-level access or above to execute arbitrary shortcodes via the search AJAX action. It was published on March 21, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium/High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), with a secondary concern of CWE-862 (Missing Authorization). The callback_search() function in navigation.action.php lacks proper capability checks, and the sanitize_text_field() sanitization used on user-supplied parameters (task_id, point_id, categories_id, term) does not strip square brackets, allowing shortcode syntax to pass through. The unsanitized input is then concatenated directly into a do_shortcode() call, enabling injection of arbitrary WordPress shortcodes (Wordfence, WordPress Trac).

Impact

Successful exploitation allows authenticated attackers (Subscriber-level and above) to execute arbitrary WordPress shortcodes, potentially exposing sensitive site content, manipulating site output, or leveraging shortcodes that trigger further server-side functionality. The confidentiality and integrity of the WordPress site are both at risk, as malicious shortcodes could be used to extract data or alter site behavior. Availability is not directly impacted, but chained exploitation with other shortcode-based vulnerabilities could escalate the impact (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.038% (0.000380), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Subscriber-level WordPress account, limiting the attack surface compared to unauthenticated vulnerabilities (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Task Manager plugin (versions ≤ 3.0.2) using tools like WPScan or by checking /wp-content/plugins/task-manager/ for plugin presence.
  2. Obtain Subscriber Access: Register or log in as a Subscriber-level (or higher) WordPress user on the target site.
  3. Craft Malicious AJAX Request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with action=search (the Task Manager search AJAX action).
  4. Inject Shortcode Payload: Include shortcode syntax in one of the vulnerable parameters (e.g., task_id, point_id, categories_id, or term), such as term=[malicious_shortcode], where [malicious_shortcode] is a registered WordPress shortcode that performs a desired action (e.g., data disclosure or file inclusion).
  5. Trigger Execution: The server-side callback_search() function passes the unsanitized input to do_shortcode(), executing the injected shortcode and returning its output in the AJAX response (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual authenticated POST requests to /wp-admin/admin-ajax.php with action=search and parameters (task_id, point_id, categories_id, term) containing square bracket shortcode syntax (e.g., [shortcode_name]).
  • Logs: WordPress access logs showing repeated AJAX requests to admin-ajax.php from Subscriber-level accounts with encoded or unusual parameter values; PHP error logs referencing do_shortcode() calls with unexpected input.
  • File System: No direct file artifacts expected, but monitor for new files created by shortcodes that invoke file-writing functionality.
  • Process: Unexpected server-side processes spawned as a result of shortcode execution (dependent on which shortcodes are available and invoked).

Mitigation and workarounds

As of the disclosure date, no patched version beyond 3.0.2 was confirmed available. Site administrators should consider deactivating and removing the Task Manager plugin until a patched version is released. As a workaround, restrict user registration and limit Subscriber-level account creation to trusted users. Monitor the official WordPress plugin repository for an updated version that addresses the missing capability check and input validation in callback_search() (Wordfence, Wordfence Weekly Report).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, and published a dedicated threat intelligence entry (Wordfence Weekly Report). The vulnerability was also picked up by several CVE aggregation and threat intelligence platforms shortly after disclosure. No significant independent researcher commentary or broader media coverage has been identified beyond standard CVE tracking.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management