CVE-2026-77013
Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method Dispatch
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.
| Vendor | unknown |
| Product | 爱采集数据采集和发布插件 |
| Published | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown 爱采集数据采集和发布插件
Be the first to know when new unknown vulnerabilities affecting unknown 爱采集数据采集和发布插件 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / 爱采集数据采集和发布插件
0 ≤ 1.0.0
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan