爱采集数据采集和发布插件 <= 1.0.0 - Unauthenticated Arbitrary File Read
high
The 爱采集数据采集和发布插件 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.0. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to read arbitrary files on the server, including sensitive configuratio...
- CVSS:
- 7.5
(Wordfence)
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 27, 2026
CVE-2026-77012 on NVD →
爱采集数据采集和发布插件 <= 1.0.0 - Missing Authorization
medium
The 爱采集数据采集和发布插件 plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
(Wordfence)
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2026
CVE-2026-77013 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database