← All CVEs NewScan detects
high

CVE-2026-86802

To Do List Member unauthenticated import - no authorisation or nonce check, and the fetched location is unvalidated (content injection + SSRF)

Severity
high
Affected product
todo-lists-for-membership-sites
Affected versions
todo-lists-for-membership-sites ≥ 1.4, ≤ 1.6
Added to NewScan
2026-09-21
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints todo-lists-for-membership-sites from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-21. Directory slug is `todo-lists-for-membership-sites`, NOT `to-do-list-member` - the plugin TITLE is 'To Do List Member' and the obvious slugification of it is wrong, which would have been a permanently dead key. Slug and the 1.4-1.6 range are ground truth from the WPScan entry (71c678eb-35f8-4eac-a4bb-b71bdcb2ca4e). Deliberately NO `fixed_in`: WPScan records no known fix, so claiming one would send customers to a release that does not exist - the remediation is removal, which the finding text has to carry instead. The import routine has neither an authorisation nor a nonce check and does not validate the location it fetches the imported data from, so an unauthenticated caller both creates arbitrary published posts and taxonomy terms AND makes the site issue a server-side request to a location of their choosing. `le` 1.6 is an inclusive upper bound for the same reason: with no fix, 1.6 itself is affected. Observation source is the readme.txt `Stable tag:` probe - this plugin is not in the wordpress.org directory (api.wordpress.org 404s the slug), so the readme probe is the only route to its version. Version-match only: the in-band proof would publish attacker-controlled posts on the customer's site.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →