CVE-2025-14064
The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0.
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view, create, modify, and delete task boards belonging to any BuddyPress group, including private and hidden groups they are not members of.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Source
- security@wordfence.com
References
- https://cwe.mitre.org/data/definitions/862.html
- https://plugins.trac.wordpress.org/browser/buddytask/tags/1.3.0/buddytask.php#L458
- https://plugins.trac.wordpress.org/browser/buddytask/trunk/buddytask.php#L458
- https://plugins.trac.wordpress.org/browser/buddytask/trunk/buddytask.php#L666
- https://plugins.trac.wordpress.org/browser/buddytask/trunk/buddytask.php#L763
- https://plugins.trac.wordpress.org/browser/buddytask/trunk/buddytask.php#L840
- https://plugins.trac.wordpress.org/changeset/3416754/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0dfe0947-5790-49ba-aa3d-6bc61c12b355?source=cve
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.