CVE-2026-39757
Received Received - Intake

Subscriber Arbitrary File Upload in Taskbot

Vulnerability report for CVE-2026-39757, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Patchstack

Description

Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
AmentoTech Taskbot n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Upload flaw in the WordPress Taskbot Plugin versions 6.6 and below. It allows attackers with Subscriber-level access to upload malicious files to the server, potentially leading to full server compromise.

Detection Guidance

Check for unauthorized file uploads in the Taskbot plugin directory. Look for unexpected files with extensions like .php, .exe, or .js in the uploads folder. Review server logs for POST requests to /wp-content/plugins/taskbot/ or similar paths.

Impact Analysis

Attackers could exploit this to upload malicious files, take over your WordPress site, or use it as a foothold for further attacks. The high CVSS score of 9.9 indicates severe risk of exploitation.

Mitigation Strategies

Disable the Taskbot plugin immediately if not essential. Apply Patchstack's mitigation rule if available. Restrict Subscriber-level access to only trusted users. Monitor server files for suspicious uploads and consider using a web application firewall.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39757. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart