External risk intelligence

WordPress LazyTasks Plugin Account Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-12963

The vulnerability exists in a WordPress plugin that exposes a REST API endpoint. WordPress sites are commonly deployed as public-facing web applications, and this plugin's functionality is directly accessible via web requests, making the vulnerable endpoint reachable from the internet in common deployment patterns.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the LazyTasks WordPress plugin allows unauthenticated attackers to take over any user account, including administrators, by changing their email addresses and resetting passwords. This privilege escalation could lead to unauthorized access and control over affected WordPress sites.

  • Plugin allows attackers to change user emails.
  • Executive leadership should remember this for website security.
  • Confirm if your WordPress sites use this plugin.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a request to a specific REST API endpoint. By manipulating user data through this endpoint, an attacker can take over an administrator's account, leading to full site compromise.

  • No authentication required.
  • Update user email via API endpoint.
  • Full account takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could take over any user account on a WordPress site running the affected plugin. This could happen by exploiting a flaw in how the plugin handles user identity when updating details through its REST API. The attacker could then reset the user's password and gain full account access.

  • User accounts and administrative access.
  • Unauthenticated API requests to change user email.
  • Complete account takeover, including administrator privileges.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WordPress plugin requires immediate attention from teams managing WordPress instances. The first step is to identify all WordPress sites utilizing this plugin, confirm if the exposed API endpoint is accessible externally, and determine the business criticality of each affected site to prioritize remediation efforts and coordinate with the vendor or responsible internal teams.

  • Own by WordPress site administrators.
  • Verify external API endpoint reachability.
  • Plan for plugin update or removal.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the LazyTasks plugin for WordPress?

LazyTasks is a WordPress plugin designed for project management and team collaboration. It provides tools for organizing tasks using Kanban boards and Gantt charts directly within a WordPress dashboard. Users typically install it to manage workflows, track project timelines, and facilitate team communication within their site infrastructure.

What is the vulnerability in CVE-2025-12963?

This vulnerability is classified as CWE-862, which is an improper authorization weakness. In plain terms, the plugin fails to verify who is making a request before allowing them to change sensitive user information. Because the software does not check for proper permissions, an unauthorized party can interact with the system as if they were a legitimate user.

How does an attacker trigger this security flaw?

An attacker triggers this by sending a specially crafted request to a specific REST API endpoint provided by the plugin. The vulnerability does not require the attacker to have an existing account or be logged into the WordPress site. Simply sending the request to the endpoint is enough to bypass security, provided the site has the plugin installed and enabled.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because this plugin exposes a REST API endpoint and WordPress sites are typically public-facing, the risk is high. Since the vulnerable endpoint is reachable over the internet in standard configurations, any WordPress site running the affected plugin versions is considered likely to be exposed to this network-based threat.

What should I do if I use the LazyTasks plugin?

First, inventory your WordPress sites to confirm if this specific plugin is active. Once identified, prioritize these instances based on their business importance. Because the flaw allows for total account takeover, you should restrict access to the plugin or remove it entirely until you can coordinate with your technical team to apply official patches or updates provided by the vendor.

References