CVE-2026-77012
Received Received - Intake

Arbitrary File Read and SSRF in 爱采集数据采集和发布插件 WordPress Plugin

Vulnerability report for CVE-2026-77012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the 爱采集数据采集和发布插件 WordPress plugin up to version 1.0.0. It lacks a per-install secret for an unauthenticated endpoint, using a hardcoded default instead. The plugin also fails to validate URLs or destination paths, enabling three main issues: arbitrary file read, Server-Side Request Forgery (SSRF), and path traversal leading to file write outside the uploads directory.

Detection Guidance

Check if the 爱采集数据采集和发布插件 (Icollect) WordPress plugin version 1.0.0 or below is installed. Test unauthenticated endpoints for arbitrary file read or SSRF by sending crafted requests to the plugin's vulnerable endpoints. Look for responses containing sensitive files or unexpected data from internal requests.

Impact Analysis

Attackers can exploit this to read sensitive files on your server, force it to make arbitrary requests and retrieve responses, and write malicious content to unintended locations outside the uploads directory. This could lead to data breaches, unauthorized access, or further compromise of your system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Non-compliance may result in legal penalties, fines, or reputational damage due to data exposure.

Mitigation Strategies

Immediately uninstall or disable the 爱采集数据采集和发布插件 (Icollect) WordPress plugin if installed. Monitor network traffic for unusual requests originating from the server. Apply any official patches or updates once released by the plugin developers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart