Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-32507 WordPress Woo Custom Emails plugin <= 2.2 - Broken Access Control vulnerability — Woo Custom Emails 7.3 High2024-12-13
CVE-2023-30490 WordPress Easing Slider plugin <= 3.0.8 - Plugin Settings Reset Vulnerability — Easing Slider 7.5 High2024-12-13
CVE-2023-28990 WordPress Viral Mag theme <= 1.0.9 - Authenticated Arbitrary Plugin Activation Vulnerability — Viral Mag 4.3 Medium2024-12-13
CVE-2023-27456 WordPress Total theme <= 2.1.19 - Authenticated Arbitrary Plugin Activation — Total 4.3 Medium2024-12-13
CVE-2023-25988 WordPress Video Gallery – YouTube Gallery plugin <= 1.7.6 - Broken Access Control vulnerability — Video Gallery – YouTube Gallery 7.5 High2024-12-13
CVE-2022-47429 WordPress Coming Soon Landing Page and Maintenance Mode WordPress Plugin plugin <= 2.2.0 - Broken Access Control — Coming Soon Landing Page and Maintenance Mode WordPress Plugin 5.3 Medium2024-12-13
CVE-2022-44578 WordPress Owl Carousel plugin <= 0.5.3 - Broken Access Control vulnerability — Owl Carousel 5.3 Medium2024-12-13
CVE-2023-22697 WordPress Survey Maker plugin <= 3.2.0 - Broken Access Control vulnerability — Survey Maker 5.3 Medium2024-12-13
CVE-2022-47594 WordPress Essential Blocks for Gutenberg plugin <= 3.8.5 - Broken Access Control — Essential Blocks for Gutenberg 6.5 Medium2024-12-13
CVE-2022-47182 WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Control — APIExperts Square for WooCommerce 5.3 Medium2024-12-13
CVE-2022-47176 WordPress Depicter Slider plugin <= 1.9.0 - Broken Access Control vulnerability — Depicter Slider 4.3 Medium2024-12-13
CVE-2022-47168 WordPress Printful Integration for WooCommerce plugin <= 2.2.3 - Cross Site Request Forgery (CSRF) — Printful Integration for WooCommerce 4.3 Medium2024-12-13
CVE-2022-46846 WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerability — Trending/Popular Post Slider and Widget 5.3 Medium2024-12-13
CVE-2022-46840 WordPress JS Help Desk plugin <= 2.7.1 - Broken Access Control — JS Help Desk – Best Help Desk & Support Plugin 5.4 Medium2024-12-13
CVE-2022-46838 WordPress JS Help Desk plugin <= 2.7.1 - Unauthenticated Settings Change Vulnerability — JS Help Desk – Best Help Desk & Support Plugin 9.1 Critical2024-12-13
CVE-2022-46811 WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRF — ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce 4.3 Medium2024-12-13
CVE-2022-46807 WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Control — Stock Sync for WooCommerce 4.3 Medium2024-12-13
CVE-2022-46796 WordPress CURCY plugin <= 2.1.25 - Unauthenticated plugin settings change vulnerability — CURCY 6.5 Medium2024-12-13
CVE-2022-46795 WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 4.7.2 - CSRF Plugin Settings Reset vulnerability — Print Invoice & Delivery Notes for WooCommerce 6.5 Medium2024-12-13
CVE-2022-45840 WordPress Auto Affiliate Links plugin <= 6.2.1.5 - Unauth. Broken Access Control vulnerability — Auto Affiliate Links 6.5 Medium2024-12-13
CVE-2022-45841 WordPress Robo Gallery plugin <= 3.2.9 - Auth. Broken Access Control vulnerability — Robo Gallery 5.4 Medium2024-12-13
CVE-2022-45826 WordPress Sunshine Photo Cart plugin <= 2.9.13 - Auth. Broken Access Control vulnerability — Sunshine Photo Cart 5.4 Medium2024-12-13
CVE-2022-45819 WordPress Popup Maker plugin <= 1.17.1 - Broken Access Control vulnerability — Popup Maker 3.5 Low2024-12-13
CVE-2022-45806 WordPress Formidable Forms plugin <= 5.5.4 - Broken Access Control vulnerability — Formidable Forms 4.3 Medium2024-12-13
CVE-2022-43472 WordPress eRoom plugin <= 1.4.6 - Broken Access Control vulnerability — eRoom – Zoom Meetings & Webinar 4.3 Medium2024-12-13
CVE-2024-10783 MainWP Child <= 5.3.3 - Missing Authorization to Unauthenticated Privilege Escalation — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites 8.1 High2024-12-13
CVE-2024-11911 WP Crowdfunding <= 2.1.12 - Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation — WP Crowdfunding 4.3 Medium2024-12-13
CVE-2024-12300 AR for WordPress <= 7.3 - Missing Authorization to Unauthenticated Limited File Upload — AR for WordPress 3.7 Low2024-12-13
CVE-2024-55879 XWiki allows RCE from script right in configurable sections — xwiki-platform 9.1 Critical2024-12-12
CVE-2024-55876 XWiki's scheduler in subwiki allows scheduling operations for any main wiki user — xwiki-platform 7.1 -2024-12-12

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.