CVE-2026-77013
WordPress Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-77013 is an unauthenticated user and term creation vulnerability (Missing Authorization) in the 爱采集数据采集和发布插件 (Icollect) WordPress plugin through version 1.0.0. The plugin fails to restrict which handler methods a request may invoke and performs no capability or nonce verification, allowing unauthenticated attackers to create WordPress user accounts and taxonomy terms. It was publicly disclosed on August 28, 2026, with the CVE assigned by WPScan. The CVSS score is 5.3 (Medium) per WPScan, though Feedly estimates the severity as High (WPScan, GitHub Advisory).

Dettagli tecnici

The root cause is CWE-862 (Missing Authorization), classified under OWASP Top 10 A5: Broken Access Control. The plugin exposes handler methods that can be invoked by any HTTP request without verifying the caller's WordPress capabilities or validating a nonce, meaning no authentication or privilege is required to trigger administrative functions. An attacker can send crafted HTTP requests directly to these unprotected handler endpoints to register new WordPress user accounts or create taxonomy terms. The PoC is scheduled for public release on September 11, 2026, to allow time for users to update (WPScan, GitHub Advisory).

Impatto

Successful exploitation allows unauthenticated remote attackers to create arbitrary WordPress user accounts and taxonomy terms without any authorization. The ability to create user accounts could enable privilege escalation if the attacker can register accounts with elevated roles, potentially leading to full site compromise. Additionally, unauthorized taxonomy term creation can corrupt site content and data integrity (WPScan, GitHub Advisory).

Sfruttabilità

There is currently no public proof-of-concept exploit available; WPScan has withheld the PoC until September 11, 2026, to allow time for patching. There is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability is trivially exploitable by unauthenticated network attackers once technical details are public (WPScan, GitHub Advisory).

Indicatori di compromesso

  • Logs: WordPress access logs showing unexpected POST requests to plugin handler endpoints (e.g., admin-ajax.php or plugin-specific action hooks) from unauthenticated sessions.
  • WordPress Database: Unexpected new user accounts in the wp_users table with no corresponding legitimate registration activity; unexpected new taxonomy terms in wp_terms.
  • Network: Repeated or automated HTTP requests to WordPress AJAX or REST API endpoints associated with the Icollect plugin from unknown IP addresses.

Mitigazione e soluzioni alternative

Users should update the 爱采集数据采集和发布插件 (Icollect) plugin to a version later than 1.0.0 once a patched release is available. As an interim workaround, site administrators should consider deactivating or removing the plugin until a fix is confirmed. Restricting access to WordPress AJAX endpoints via firewall rules or a web application firewall (WAF) can reduce exposure. Ensure all WordPress plugins implement proper capability checks and nonce verification on all handler methods (WPScan, GitHub Advisory).

Reazioni della comunità

The vulnerability was discovered and submitted by Pablo González Pérez, Francisco José Ramírez Vicente, and Iñigo Sánchez Enciso, affiliated with Telefónica. WPScan verified the report and is withholding the PoC until September 11, 2026, following responsible disclosure practices (WPScan).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato WordPress Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-77013NONEN/A
  • icollect
NoNoAug 31, 2026
CVE-2026-81766NONEN/A
  • really-simple-ssl
NoAug 30, 2026
CVE-2026-81660NONEN/A
  • groundhogg
NoAug 30, 2026
CVE-2026-78364NONEN/A
  • mw-wp-form
NoAug 30, 2026
CVE-2026-76585NONEN/A
  • customer-reviews-woocommerce
NoAug 30, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità