CVE-2026-86802
3.7 LOWPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated users to create arbitrary published posts and taxonomy terms by exploiting a lack of authorization and nonce checks in the import routine.
- Exploitability
- Exploitation requires access to the import feature, making it moderately difficult but feasible for attackers with knowledge of the plugin version.
- Blast radius
- If exploited, this could lead to unauthorized content creation on the WordPress site, potentially impacting user trust and site integrity.
- Prioritized remediation
- Update to the latest version of the To Do List Member WordPress plugin, which should address these security issues.
auth-bypasswebwordpresscontent-injection
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-862
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-16605
- HIGHCVE-2026-15372
- HIGHCVE-2026-15979
- HIGHCVE-2026-16036
- HIGHCVE-2026-16736
- HIGHCVE-2026-6147
- HIGHCVE-2026-7693
- CRITICALCVE-2026-15958
Related by shared AI tags and CWE weakness class. Browse the full archive.