Impact
The vulnerability in the 爱采集数据采集和发布插件 allows an attacker to freely invoke any handler method exposed by the plugin. Because the plugin performs no capability or nonce checks, unauthenticated users can create new WordPress user accounts and taxonomy terms. This can elevate an attacker’s privileges, provide an entry into the site’s administrative back‑end, and enable further exploitation such as content injection or credential dumping.
Affected Systems
All installations of this WordPress plugin with a version of 1.0.0 or earlier are affected. The vendor is unknown; the product is the "爱采集数据采集和发布插件" plugin.
Risk and Exploitability
The vulnerability carries a moderate exploitation risk with a CVSS score of 5.3 due to the lack of authentication checks, and its EPSS score indicates a very low likelihood of exploitation (<1%). Attacks can occur over the public web by sending specially crafted requests to the plugin’s endpoints and do not require pre-existing accounts. The lack of a patch or mitigation recommendation in the public feed means any site running the vulnerable plugin is exposed until a new version is released or the plugin is removed.
OpenCVE Enrichment