CVE-2026-86802: To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import

Published Sep 21, 2026
·
Updated

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.

Affected Software

1 affected component
WordPress To Do List Member<=1.6

Event History

Sep 21, 2026
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote user can exploit it. No account, authorization, or nonce is required for the affected import routine.

2

What could an attacker change on an affected site?

An attacker can create arbitrary published posts and taxonomy terms. The provided information does not indicate confidentiality impact or service disruption.

3

Which plugin versions are affected?

The issue affects To Do List Member versions through 1.6. The supplied data does not identify a fixed version.

4

What is required for exploitation?

The attacker must be able to reach the vulnerable import routine and provide an imported-data location. Exploitation is rated as high complexity, but no further prerequisites are provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203