CVE-2026-4004
Last modified
CVE-2026-4004 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode syntax (square brackets) to pass through sanitize_text_field() and be concatenated into a do_shortcode() call. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode syntax (square brackets) to pass through sanitize_text_field() and be concatenated into a do_shortcode() call. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes on the site by injecting shortcode syntax into parameters like 'task_id', 'point_id', 'categories_id', or 'term'.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4004?
How severe is CVE-2026-4004?
How do I fix CVE-2026-4004?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40034gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix bef…8.5
- CVE-2026-40035Unfurl through 2025.08 contains an improper input validation…9.3
- CVE-2026-40036Unfurl before 2026.04 contains an unbounded zlib decompressi…8.7
- CVE-2026-40037OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a r…7.1
- CVE-2026-40038Pachno 1.0.6 contains a stored cross-site scripting vulnerab…7.2
- CVE-2026-40039Pachno 1.0.6 contains an open redirection vulnerability that…7.1
- CVE-2026-40040Pachno 1.0.6 contains an unrestricted file upload vulnerabil…8.8
- CVE-2026-40041Pachno 1.0.6 contains a cross-site request forgery vulnerabi…5.3
- CVE-2026-40042Pachno 1.0.6 contains an XML external entity injection vulne…9.8
- CVE-2026-40043Pachno 1.0.6 contains an authentication bypass vulnerability…7.1
- CVE-2026-40044Pachno 1.0.6 contains a deserialization vulnerability that a…9.8
- CVE-2026-40045OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:/…5.9
Are you affected by CVE-2026-4004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
