Unauthenticated Endpoint Vulnerability in 爱采集数据采集和发布 Plugin for WordPress
CVE-2026-77012
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 29 August 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-77012?
The 爱采集数据采集和发布 plugin for WordPress is vulnerable due to its unauthenticated endpoints that use a hardcoded default secret. This flaw permits unauthorized attackers to execute file reading operations, send arbitrary requests, and write content outside designated upload paths, which significantly compromises server integrity and exposes sensitive data.
Affected Version(s)
爱采集数据采集和发布插件 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.