PT-2026-94184 · WordPress · To Do List Member

CVE-2026-86801

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions To Do List Member versions 1.4 through 1.6
Description The plugin includes a file upload endpoint that operates independently of the WordPress core, bypassing authentication, capability, and nonce checks. Because the system validates only the filename and not the actual content, unauthenticated users can upload and store active content served from the site origin. Additionally, this flaw allows unauthorized users to list and delete files already present in the upload directory.
Recommendations Update To Do List Member to a version later than 1.6. As a temporary mitigation, restrict access to the file upload endpoint to prevent unauthorized file uploads, listing, and deletion.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86801

Affected Products

To Do List Member