{"id":"CVE-2026-86802","published":"2026-09-21T09:17:06.157","lastModified":"2026-09-21T15:17:33.130","description":"The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.","cvssScore":3.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/71c678eb-35f8-4eac-a4bb-b71bdcb2ca4e/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to create arbitrary published posts and taxonomy terms by exploiting a lack of authorization and nonce checks in the import routine.","exploitability":"Exploitation requires access to the import feature, making it moderately difficult but feasible for attackers with knowledge of the plugin version.","blast_radius":"If exploited, this could lead to unauthorized content creation on the WordPress site, potentially impacting user trust and site integrity.","remediation":"Update to the latest version of the To Do List Member WordPress plugin, which should address these security issues.","tags":["auth-bypass","web","wordpress","content-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:36:03.388Z"}}