← Back to search

CVE-2026-86802

3.7 LOW

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated users to create arbitrary published posts and taxonomy terms by exploiting a lack of authorization and nonce checks in the import routine.
Exploitability
Exploitation requires access to the import feature, making it moderately difficult but feasible for attackers with knowledge of the plugin version.
Blast radius
If exploited, this could lead to unauthorized content creation on the WordPress site, potentially impacting user trust and site integrity.
Prioritized remediation
Update to the latest version of the To Do List Member WordPress plugin, which should address these security issues.
auth-bypasswebwordpresscontent-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.