CVE-2026-86802: To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import
The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote user can exploit it. No account, authorization, or nonce is required for the affected import routine.
What could an attacker change on an affected site?
An attacker can create arbitrary published posts and taxonomy terms. The provided information does not indicate confidentiality impact or service disruption.
Which plugin versions are affected?
The issue affects To Do List Member versions through 1.6. The supplied data does not identify a fixed version.
What is required for exploitation?
The attacker must be able to reach the vulnerable import routine and provide an imported-data location. Exploitation is rated as high complexity, but no further prerequisites are provided.