Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11724 Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent 4.3 Medium2024-12-12
CVE-2024-12201 Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creation — Hash Form – Drag & Drop Form Builder 4.3 Medium2024-12-12
CVE-2024-12263 Child Theme Creator by Orbisius <= 1.5.5 - Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete — Child Theme Creator by Orbisius 4.3 Medium2024-12-12
CVE-2024-12265 Web3 Cryptocurrency Payments by DePay for WooCommerce <= 2.12.17 - Missing Authorization to Information Exposure — Web3 Crypto Payments by DePay for WooCommerce 5.3 Medium2024-12-12
CVE-2024-12172 WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update — WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses 7.5 High2024-12-12
CVE-2024-12018 Snippet Shortcodes <= 4.1.6 - Authenticated (Subscriber+) Shortcode Deletion — Snippet Shortcodes 4.3 Medium2024-12-12
CVE-2024-11709 AI Post Generator | AutoWriter <= 3.5 - Missing Authorization to Authenticated (Contributor+) Post/Page Deletion — AI Post Generator | AutoWriter 4.3 Medium2024-12-12
CVE-2024-11443 de:branding <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Update — de:branding 8.8 High2024-12-12
CVE-2024-12341 Custom Skins Contact Form 7 <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update and Skin Creation — Custom Skins Contact Form 7 4.3 Medium2024-12-12
CVE-2024-11840 RapidLoad – Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection — RapidLoad AI – Optimize Web Vitals Automatically 7.1 High2024-12-11
CVE-2024-11401 Rapid7 Insight Platform Privilege Escalation Vulnerability — Insight Platform 8.1 -2024-12-11
CVE-2024-54269 WordPress Notibar plugin <= 2.1.4 - Broken Access Control vulnerability — Notibar 4.3 Medium2024-12-11
CVE-2024-11205 WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation — WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More 8.5 High2024-12-10
CVE-2024-47585 Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP Platform 4.3 Medium2024-12-10
CVE-2024-47581 Missing Authorization check in SAP HCM (Approve Timesheets version 4) — SAP HCM 4.3 Medium2024-12-10
CVE-2024-45760 Dell OpenManage Server Administrator 安全漏洞 — Dell OpenManage Server Administrator 4.3 Medium2024-12-09
CVE-2023-41953 WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability — ProfilePress 5.3 Medium2024-12-09
CVE-2024-54218 WordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Plugin Settings Change vulnerability — AIO Contact 6.5 Medium2024-12-09
CVE-2024-52391 WordPress Pie Register Premium plugin < 3.8.3.3 - Broken Access Control vulnerability — Pie Register Premium 5.3 Medium2024-12-09
CVE-2024-52480 WordPress Jobify plugin < 4.3.0 - Broken Access Control vulnerability — Jobify 5.3 Medium2024-12-09
CVE-2024-53785 WordPress Chatter plugin <= 1.0.1 - Broken Access Control vulnerability — Chatter 4.3 Medium2024-12-09
CVE-2024-53816 WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerability — Tutor LMS Elementor Addons 4.3 Medium2024-12-09
CVE-2024-54217 WordPress ARForms plugin <= 6.4.1 - Subscriber+ Plugin Settings Change vulnerability — ARForms 5.4 Medium2024-12-09
CVE-2024-53798 WordPress FloristPress plugin <= 7.3.0 - Nonce Leakage to Broken Access Control vulnerability — FloristPress 5.4 Medium2024-12-09
CVE-2024-54254 WordPress Message Filter for Contact Form 7 plugin <= 1.6.3 - Broken Access Control vulnerability — Message Filter for Contact Form 7 6.3 Medium2024-12-09
CVE-2024-53819 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.0 - Insecure Direct Object References (IDOR) vulnerability — Client Invoicing by Sprout Invoices 5.3 Medium2024-12-09
CVE-2024-43222 WordPress Sweet Date theme <= 3.7.3 - Privilege Escalation vulnerability — Sweet Date 9.8 Critical2024-12-09
CVE-2023-48277 WordPress Super Progressive Web Apps plugin <= 2.2.21 - Broken Access Control vulnerability — Super Progressive Web Apps 4.3 Medium2024-12-09
CVE-2024-54227 WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.0.0 - Broken Access Control vulnerability — Minimum and Maximum Quantity for WooCommerce 4.3 Medium2024-12-09
CVE-2024-54251 WordPress Prodigy Commerce plugin <= 3.1.2 - Broken Access Control vulnerability — Prodigy Commerce 6.5 Medium2024-12-09

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.