Back

LOW

To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import

Published Sep 21, 2026

Description

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Sep 21, 2026
Updated Sep 21, 2026
Reserved Sep 8, 2026

CISA Vulnrichment

Updated Sep 21, 2026

NVD

Status Deferred
Modified Sep 21, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Sep 21, 2026
Updated Sep 21, 2026

GitHub

No data