Impact
The To Do List Member WordPress plugin includes a file upload endpoint that bypasses any WordPress authentication, capability, or nonce checks and validates only the filename, not the file content. This oversight allows an attacker to upload active files such as JavaScript, which are then served from the site’s own origin, resulting in persistent cross‑site scripting that executes in the context of any visitor who accesses that file. In addition to stored XSS, the unauthenticated endpoint permits attackers to list and delete files that have already been uploaded, further compromising the site’s integrity and availability.
Affected Systems
Any WordPress installation running the To Do List Member plugin versions 1.4, 1.5, or 1.6 is vulnerable. The plug‑in’s name is the only vendor identifier provided, and no additional vendor or product details are specified, so all sites that have these plugin versions active are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity due to remote stored XSS and lack of authentication. The EPSS score of less than 1% suggests that, at present, exploitation is considered unlikely, and it is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability simply by accessing a publicly available upload URL, and successful exploitation gives them persistent script execution in the site’s origin context, which can lead to data exposure, session hijacking, or site takeover.
OpenCVE Enrichment