PT-2026-94184 · WordPress · To Do List Member
CVE-2026-86801
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
To Do List Member versions 1.4 through 1.6
Description
The plugin includes a file upload endpoint that operates independently of the WordPress core, bypassing authentication, capability, and nonce checks. Because the system validates only the filename and not the actual content, unauthenticated users can upload and store active content served from the site origin. Additionally, this flaw allows unauthorized users to list and delete files already present in the upload directory.
Recommendations
Update To Do List Member to a version later than 1.6.
As a temporary mitigation, restrict access to the file upload endpoint to prevent unauthorized file uploads, listing, and deletion.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
To Do List Member