Impact
The To Do List Member plugin for WordPress lacks authorization checks and nonce validation in its import routine, and it does not verify the origin of data it imports. As a result, an unauthenticated attacker can trigger the import endpoint to create arbitrary published posts and taxonomy terms on the site, potentially leading to content defacement or the spread of malicious material. The vulnerability stems from improper access control and insufficient input validation, allowing attackers to inject arbitrary content without authentication.
Affected Systems
The affected product is the To Do List Member WordPress plugin, versions 1.4 through 1.6. These versions are distributed under an unknown vendor label and run within standard WordPress installations on PHP‑enabled web servers. Users who upgrade to newer releases that address the issue or apply the vendor’s fix will no longer be susceptible to this injection flaw.
Risk and Exploitability
The CVSS v3 score of 3.7 places this vulnerability in the low‑moderate range, and the EPSS score is not available. It is not listed in the CISA KEV catalog, suggesting no confirmed exploits. The attack vector is inferred to be unauthenticated HTTP requests to the import endpoint; therefore, the risk depends on the public exposure of the plugin. Given the lack of identified exploits, the immediate threat is moderate but should be mitigated promptly.
OpenCVE Enrichment