PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77013 WordPress CVE debrief

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms, potentially leading to unauthorized access and content modification. Affected WordPress installations should prioritize updating or mitigating this plugin to prevent exploitation. The CVE record was published on 2026-08-31T07:17:45.980Z and has not been modified since then. Defenders should verify the presence of this plugin in their WordPress installations and review user account creation and taxonomy term management processes. The vulnerability has a high impact on the confidentiality, integrity, and availability of the affected systems.

Vendor
WordPress
Product
爱采集数据采集和发布插件
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-31
Original CVE updated
2026-08-31
Advisory published
2026-08-31
Advisory updated
2026-08-31

Who should care

WordPress users and administrators who have the 爱采集数据采集和发布插件 installed should be aware of this vulnerability and take immediate action to protect their installations. This includes verifying the presence of the plugin, restricting access to user account creation and taxonomy term management, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

Technical summary

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms, potentially leading to unauthorized access and content modification. Affected WordPress installations should prioritize updating or mitigating this plugin to prevent exploitation.

Defensive priority

Unauthenticated users can create WordPress user accounts and taxonomy terms due to a lack of access controls in the 爱采集数据采集和发布插件 WordPress plugin.

Recommended defensive actions

  • Inventory and verify installed plugins on WordPress installations.
  • Restrict access to WordPress user account creation and taxonomy term management.
  • Monitor for suspicious user account creation and taxonomy term changes.
  • Consider implementing additional security controls such as Web Application Firewalls (WAFs) or intrusion detection systems.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE description indicates that the 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them. This lack of access control allows unauthenticated users to create WordPress user accounts and taxonomy terms. Defenders should verify the presence of this plugin in their WordPress installations and review user account creation and taxonomy term management processes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77013 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77013

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77013 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77013

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.