PT-2026-96059 · WordPress · To Do List Member
CVE-2026-86802
·
Published
2026-09-21
·
Updated
2026-09-24
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
To Do List Member WordPress plugin versions prior to 1.7
Description
An import routine lacks authorization and nonce checks, and fails to validate the source location of fetched data. This allows unauthenticated users to create arbitrary published posts and taxonomy terms on the site. A nonce is a unique token used to prevent replay attacks by ensuring that a request is intentional and not forged.
Recommendations
Update the plugin to version 1.7 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
To Do List Member