Description
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Account and Term Creation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the 爱采集数据采集和发布插件 allows an attacker to freely invoke any handler method exposed by the plugin. Because the plugin performs no capability or nonce checks, unauthenticated users can create new WordPress user accounts and taxonomy terms. This can elevate an attacker’s privileges, provide an entry into the site’s administrative back‑end, and enable further exploitation such as content injection or credential dumping.

Affected Systems

All installations of this WordPress plugin with a version of 1.0.0 or earlier are affected. The vendor is unknown; the product is the "爱采集数据采集和发布插件" plugin.

Risk and Exploitability

The vulnerability carries a moderate exploitation risk with a CVSS score of 5.3 due to the lack of authentication checks, and its EPSS score indicates a very low likelihood of exploitation (<1%). Attacks can occur over the public web by sending specially crafted requests to the plugin’s endpoints and do not require pre-existing accounts. The lack of a patch or mitigation recommendation in the public feed means any site running the vulnerable plugin is exposed until a new version is released or the plugin is removed.

Generated by OpenCVE AI on August 31, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the "爱采集数据采集和发布插件" plugin to the latest available version that addresses the unrestricted method dispatch flaw.
  • If a newer patch is not available, permanently deactivate or uninstall the plugin to stop the vulnerability from being exploitable.
  • Apply general WordPress hardening steps, such as disabling REST API exposure, enforcing SSL, and limiting user roles, to reduce the impact should the plugin remain in use.

Generated by OpenCVE AI on August 31, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 31 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 31 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.
Title Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method Dispatch
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-31T12:38:05.781Z

Reserved: 2026-08-20T07:43:19.655Z

Link: CVE-2026-77013

cve-icon Vulnrichment

Updated: 2026-08-31T12:29:47.031Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T07:17:45.980

Modified: 2026-08-31T20:14:36.250

Link: CVE-2026-77013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses