Vulnerability Description
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files already staged there.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-86801?
CVE-2026-86801 is a vulnerability with a CVSS score of 8.8 (HIGH). The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, an...
How severe is CVE-2026-86801?
CVE-2026-86801 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-86801?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.