PT-2025-42281 · WordPress · Wordpress Task Scheduler

Published

2025-10-15

·

Updated

2025-10-15

·

CVE-2025-10056

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Task Scheduler plugin versions prior to 1.6.4
Description The Task Scheduler plugin for WordPress is susceptible to Server-Side Request Forgery. This affects authenticated attackers with Administrator-level access or higher. Attackers can leverage the “Check Website” task to make web requests to arbitrary locations from the web application. This can potentially allow querying and modification of information from internal services.
Recommendations Update the Task Scheduler plugin to version 1.6.4 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10056

Affected Products

Wordpress Task Scheduler