SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77013

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The 爱采集数据采集和发布插件 for WordPress, up to version 1.0.0, is vulnerable due to insufficient restrictions on handler methods, enabling unauthenticated users to create WordPress user accounts and taxonomy terms without proper checks. This flaw poses a significant risk of unauthorized access and potential account takeover. WordPress site administrators using this plugin should prioritize immediate updates or remediation to mitigate the risk.

CVE
CVE-2026-77013
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.