Sceawere
Vulnerability Detail
CVE-2026-39757UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Taskbot Subscriber Arbitrary File Upload
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 16h ago
- Vendor
- AmentoTech
- Product
- Taskbot
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-06T09:17:47.553Z",
"pubdate": "2026-10-06T09:17:47.553Z",
"executiveSummary": "The Taskbot plugin for WordPress, specifically versions 6.6 and below, contains a critical security vulnerability involving improper validation of file uploads. The vulnerability is classified as an Unrestricted File Upload flaw, allowing authenticated users with low-level subscriber privileges to bypass security controls and upload arbitrary files, including executable scripts, to the server.\nThis vulnerability poses a severe risk to the confidentiality, integrity, and availability of the affected WordPress site. An attacker who has obtained subscriber-level access can leverage this defect to achieve Remote Code Execution (RCE) by uploading malicious web shells or other server-side scripts. Once executed, these scripts can grant the attacker full control over the web application environment, enabling them to exfiltrate sensitive database information, modify site content, or pivot into the underlying server infrastructure.\nGiven that registration is often enabled on WordPress sites, the barrier to exploitation is low, requiring only a standard subscriber account. The vulnerability persists across all versions up to 6.6, necessitating immediate defensive action from administrators to prevent compromise of the server environment and potential full site takeover.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient server-side validation of user-supplied files within the Taskbot plugin's file upload functionality. While the application may implement client-side checks or weak file extension filtering, it fails to perform robust, mime-type-based validation or extension verification on the server side prior to moving the uploaded file to its final, publicly accessible directory.\nThe attack flow begins with an attacker authenticating to the target WordPress site using valid credentials assigned to the subscriber role. Upon authentication, the attacker identifies the endpoint responsible for handling file uploads, such as profile photo updates or document submission forms within Taskbot. By intercepting the HTTP POST request using a proxy tool like Burp Suite, the attacker modifies the request to include a malicious payload, typically a PHP-based web shell, disguised with a manipulated or appended file extension if necessary to bypass basic filters.\nBecause the server fails to sanitize the input or restrict the execution context of the destination directory, the malicious file is successfully stored on the server's filesystem. Once uploaded, the attacker discovers the path of the stored file—often predictable within the /wp-content/uploads/ or similar directory structure—and triggers execution by navigating to the URL of the malicious script. The web server executes the code under the context of the service user (e.g., www-data), granting the attacker the ability to execute arbitrary system commands, interact with the local filesystem, and interface with the WordPress database directly.\nThis vulnerability is particularly dangerous because it does not require administrative privileges; a subscriber-level account is sufficient to initiate the attack. The lack of proper sanitization at the function level allows for the bypass of intended restrictions, effectively escalating the user's privilege level from a restricted subscriber to a system-level attacker. The scope of impact is comprehensive, as successful exploitation enables persistent access through the deployment of backdoors, full data extraction, and potential lateral movement within the network if the server environment is not sufficiently isolated."
}