
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77013 is an unauthenticated user and term creation vulnerability (Missing Authorization) in the 爱采集数据采集和发布插件 (Icollect) WordPress plugin through version 1.0.0. The plugin fails to restrict which handler methods a request may invoke and performs no capability or nonce verification, allowing unauthenticated attackers to create WordPress user accounts and taxonomy terms. It was publicly disclosed on August 28, 2026, with the CVE assigned by WPScan. The CVSS score is 5.3 (Medium) per WPScan, though Feedly estimates the severity as High (WPScan, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization), classified under OWASP Top 10 A5: Broken Access Control. The plugin exposes handler methods that can be invoked by any HTTP request without verifying the caller's WordPress capabilities or validating a nonce, meaning no authentication or privilege is required to trigger administrative functions. An attacker can send crafted HTTP requests directly to these unprotected handler endpoints to register new WordPress user accounts or create taxonomy terms. The PoC is scheduled for public release on September 11, 2026, to allow time for users to update (WPScan, GitHub Advisory).
Successful exploitation allows unauthenticated remote attackers to create arbitrary WordPress user accounts and taxonomy terms without any authorization. The ability to create user accounts could enable privilege escalation if the attacker can register accounts with elevated roles, potentially leading to full site compromise. Additionally, unauthorized taxonomy term creation can corrupt site content and data integrity (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available; WPScan has withheld the PoC until September 11, 2026, to allow time for patching. There is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability is trivially exploitable by unauthenticated network attackers once technical details are public (WPScan, GitHub Advisory).
wp_users table with no corresponding legitimate registration activity; unexpected new taxonomy terms in wp_terms.Users should update the 爱采集数据采集和发布插件 (Icollect) plugin to a version later than 1.0.0 once a patched release is available. As an interim workaround, site administrators should consider deactivating or removing the plugin until a fix is confirmed. Restricting access to WordPress AJAX endpoints via firewall rules or a web application firewall (WAF) can reduce exposure. Ensure all WordPress plugins implement proper capability checks and nonce verification on all handler methods (WPScan, GitHub Advisory).
The vulnerability was discovered and submitted by Pablo González Pérez, Francisco José Ramírez Vicente, and Iñigo Sánchez Enciso, affiliated with Telefónica. WPScan verified the report and is withholding the PoC until September 11, 2026, following responsible disclosure practices (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."