To Do List Member

WordPress plugin · to-do-list-member · WordPress.org ↗
0
Critical
1
High
2
Known total
2
Unfixed
Running To Do List Member on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler
CVE.org
<=1.6 unfixed CVE-2026-86801 Sep 17, 2026
LOW
CVSS 3.7
To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import
CVE.org
<=1.6 unfixed CVE-2026-86802 Sep 21, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.