CRITICAL 9.3 CVE-2026-77012 Published 29 Aug 2026

WordPress Plugin File Read/Write Vulnerability

Worried this affects one of your servers?

The 爱采集数据采集和发布插件 WordPress plugin, versions 1.0.0 and earlier, is affected. It allows unauthenticated attackers to:

  • Read arbitrary files from the server
  • Force the server to issue arbitrary requests and retrieve responses
  • Write attacker-supplied content outside the uploads directory

This is due to the plugin not requiring a per-install secret for one of its unauthenticated endpoints and not validating URLs or destination paths.

Reference: CVE-2026-77012 on NVD

← Back to Security News