CVE-2025-14064

MEDIUM

BuddyTask <1.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view, create, modify, and delete task boards belonging to any BuddyPress group, including private and hidden groups they are not members of.

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 8.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
cytechltd/BuddyTask < 1.3.0
Published Dec 12, 2025
Tracked Since Feb 18, 2026