Description
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files already staged there.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored XSS
Action: Immediate Patch
AI Analysis

Impact

The To Do List Member WordPress plugin includes a file upload endpoint that bypasses any WordPress authentication, capability, or nonce checks and validates only the filename, not the file content. This oversight allows an attacker to upload active files such as JavaScript, which are then served from the site’s own origin, resulting in persistent cross‑site scripting that executes in the context of any visitor who accesses that file. In addition to stored XSS, the unauthenticated endpoint permits attackers to list and delete files that have already been uploaded, further compromising the site’s integrity and availability.

Affected Systems

Any WordPress installation running the To Do List Member plugin versions 1.4, 1.5, or 1.6 is vulnerable. The plug‑in’s name is the only vendor identifier provided, and no additional vendor or product details are specified, so all sites that have these plugin versions active are at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity due to remote stored XSS and lack of authentication. The EPSS score of less than 1% suggests that, at present, exploitation is considered unlikely, and it is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability simply by accessing a publicly available upload URL, and successful exploitation gives them persistent script execution in the site’s origin context, which can lead to data exposure, session hijacking, or site takeover.

Generated by OpenCVE AI on September 18, 2026 at 02:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or uninstall the To Do List Member plugin if it is not required.
  • Block requests to the plugin’s upload endpoint with a web‑server rule that returns a 403 or 404 status, preventing unauthenticated uploads.
  • Upgrade to a patched version of the plugin that implements proper WordPress authentication, nonce validation, and content validation, or replace it with a secure alternative that follows best practices for file uploads.

Generated by OpenCVE AI on September 18, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files already staged there.
Title To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:09:48.670Z

Reserved: 2026-09-08T12:23:05.823Z

Link: CVE-2026-86801

cve-icon Vulnrichment

Updated: 2026-09-17T12:07:48.006Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T07:16:28.413

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function