PT-2025-50850 · Cytechltd+1 · Buddytask
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BuddyTask versions prior to 1.3.1
Description
Authenticated users with Subscriber-level access and above can gain unauthorized access to and modify data due to a missing capability check on multiple AJAX endpoints. This allows attackers to view, create, modify, and delete task boards within any BuddyPress group, including private and hidden groups where they lack membership.
Recommendations
Update BuddyTask to a version later than 1.3.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buddytask