---
id: CVE-2026-86802
title: >-
  The To Do List Member WordPress plugin through 1.6 does not have authorisation
  or nonce checks in an import routine, and does not validate the location it
  fetches the imported data from, allowing unauthenticated users to create
  arbitrary…
summary: >-
  The To Do List Member WordPress plugin through 1.6 does not have authorisation
  or nonce checks in an import routine, and does not validate the location it
  fetches the imported data from, allowing unauthenticated users to create
  arbitrary…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: To Do List Member
affected:
  - to_do_list_member >= 1.4 <= 1.6
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T15:17:33.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86802'
references:
  - url: 'https://wpscan.com/vulnerability/71c678eb-35f8-4eac-a4bb-b71bdcb2ca4e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T13:56:30.367751Z'
epss: 0.00158
epssPercentile: 0.05374
ingestedAt: '2026-09-21T09:34:37.180Z'
---

## Overview

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
