CyberRota Analysis
AI-GeneratedThe 爱采集数据采集和发布 plugin for WordPress versions up to 1.0.0 is vulnerable due to its reliance on a hardcoded default secret for an unauthenticated endpoint, which lacks proper URL and destination path validation. This flaw allows unauthenticated attackers to read arbitrary files, issue unauthorized requests, and write malicious content outside the designated uploads directory. WordPress site administrators using this plugin should prioritize addressing this vulnerability to mitigate potential data breaches and unauthorized access.
Original NVD Description
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory.