CVE-2026-77013

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 07:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-77013

Mitre link : CVE-2026-77013

CVE.ORG link : CVE-2026-77013


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization