CVE-2026-86801

HIGH CVSS 3.1: 8.8 EPSS 0.34%
Updated Sep 18, 2026
Unknown
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions 1.4 — 1.6
Type CWE-306 (Missing Authentication for Critical Function), CWE-306 Missing Authentication for Critical Function
Vendor Unknown
Public PoC No

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files already staged there.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

unknown:to do list member