SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-77012

CRITICAL · CVSS 9.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The 爱采集数据采集和发布 plugin for WordPress versions up to 1.0.0 is vulnerable due to its reliance on a hardcoded default secret for an unauthenticated endpoint, which lacks proper URL and destination path validation. This flaw allows unauthenticated attackers to read arbitrary files, issue unauthorized requests, and write malicious content outside the designated uploads directory. WordPress site administrators using this plugin should prioritize addressing this vulnerability to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-77012
Severity
CRITICAL
CVSS
9.3
EPSS
0.20%
WordPress

Original NVD Description

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory.