CVE-2026-77013
Received Received - Intake

Unauthenticated User Account Creation in 爱采集数据采集和发布插件 WordPress Plugin

Vulnerability report for CVE-2026-77013, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: WPScan

Description

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin Icollect version 1.0.0 or below. It allows unauthenticated users to create WordPress user accounts and taxonomy terms because the plugin does not restrict which handler methods can be invoked via requests. No capability or nonce checks are performed, enabling unauthorized actions.

Detection Guidance

Check if the 爱采集数据采集和发布插件 WordPress plugin version 1.0.0 or below is installed. Look for unauthorized user accounts or taxonomy terms created without authentication.

Impact Analysis

An attacker could exploit this to create unauthorized user accounts or taxonomy terms on your WordPress site without authentication. This could lead to unauthorized access, data manipulation, or further attacks on your site.

Compliance Impact

This vulnerability could lead to unauthorized user account creation and taxonomy term modifications, potentially violating data integrity and access control requirements in GDPR and HIPAA. Unrestricted method dispatch and lack of capability checks may enable unauthorized data access or modification, compromising compliance with these regulations.

Mitigation Strategies

Remove or disable the 爱采集数据采集和发布插件 WordPress plugin immediately. Monitor for suspicious user account or taxonomy term creation until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77013. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart