A vulnerability has been found in Taskbuilder Plugin up to 5.0.9 on WordPress and classified as critical. Affected by this issue is the function
wpdb->prepare. The manipulation of the argument wppm_proj_filter leads to sql injection.
This vulnerability is listed as CVE-2026-15267. The attack may be initiated remotely. There is no available exploit.