CyberRota Analysis
AI-GeneratedThe 爱采集数据采集和发布插件 for WordPress, up to version 1.0.0, is vulnerable due to insufficient restrictions on handler methods, enabling unauthenticated users to create WordPress user accounts and taxonomy terms without proper checks. This flaw poses a significant risk of unauthorized access and potential account takeover. WordPress site administrators using this plugin should prioritize immediate updates or remediation to mitigate the risk.
Original NVD Description
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms.