CVE 9.8 CRITICAL

LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation_CVE-2025-12963

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's identity via the 'wp-json/lazytasks/api/v1/user/role/edit/' REST API endpoint prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. It is also possible for attackers to abuse this endpoint to grant users with access to additional roles within the plugin

AI Analysis

Privilege escalation via account takeover due to missing authorization in the 'wp-json/lazytasks/api/v1/user/role/edit/' REST API endpoint

Basic Information

ID CVE-2025-12963
Source Wordfence
Published Dec 12, 2025 at 03:20

Affected Product

Vendor lazycoders
Product LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
Version *
Affected Versions lazycoders LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor lazycoders
Product LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
Version 1.2.29

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.