The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-31 07:17
Updated : 2026-08-31 20:14
NVD link : CVE-2026-77013
Mitre link : CVE-2026-77013
CVE.ORG link : CVE-2026-77013
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
