Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10674 Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation — Th Shop Mania 8.8 High2024-11-09
CVE-2024-10673 Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation — Top Store 8.8 High2024-11-09
CVE-2024-10294 CE21 Suite <= 2.2.0 - Missing Authorization to Unauthenticated Plugin Settings Change — CE21 Suite 6.5 Medium2024-11-09
CVE-2024-10586 Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation — Debug Tool 9.8 Critical2024-11-09
CVE-2024-10588 Debug Tool <= 2.2 - Missing Authorization to Information Exposure — Debug Tool 4.3 Medium2024-11-09
CVE-2024-10824 Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert Data — Enterprise Server 4.3AIMediumAI2024-11-07
CVE-2024-6626 EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 - Missing Authorization — EleForms – All In One Form Integration including DB for Elementor 5.3 Medium2024-11-06
CVE-2024-10543 Tumult Hype Animations <= 1.9.14 - Missing Authorization — Tumult Hype Animations 4.3 Medium2024-11-06
CVE-2024-10535 Video Gallery for WooCommerce <= 1.31 - Missing Authorization to Unauthenticated Limited File Deletion — Video Gallery for WooCommerce 5.3 Medium2024-11-06
CVE-2024-51516 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.2 Medium2024-11-05
CVE-2024-37209 WordPress User Rights Access Manager plugin <= 1.1.2 - Broken Access Control vulnerability — User Rights Access Manager 6.5 Medium2024-11-01
CVE-2024-48045 WordPress Happy Elementor Addons plugin <= 3.12.3 - Broken Access Control vulnerability — Happy Addons for Elementor 4.3 Medium2024-11-01
CVE-2024-48044 WordPress ShortPixel Image Optimizer plugin <= 5.6.3 - Broken Access Control vulnerability — ShortPixel Image Optimizer 5.4 Medium2024-11-01
CVE-2024-48039 WordPress CubeWP Framework plugin <= 1.1.15 - Broken Access Control vulnerability — CubeWP 4.3 Medium2024-11-01
CVE-2024-47314 WordPress Sunshine Photo Cart plugin <= 3.2.8 - Broken Access Control vulnerability — Sunshine Photo Cart 7.1 High2024-11-01
CVE-2024-47311 WordPress Wheel of Life plugin <= 1.1.8 - Broken Access Control vulnerability — Wheel of Life 5.3 Medium2024-11-01
CVE-2024-47302 WordPress Fluent Support plugin <= 1.8.0 - Broken Access Control on Email Verification vulnerability — Fluent Support 5.3 Medium2024-11-01
CVE-2024-44038 WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerability — Sunshine Photo Cart 5.3 Medium2024-11-01
CVE-2024-37250 WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Subscriber+ Broken Access Control vulnerability — Advanced Custom Fields PRO 5.4 Medium2024-11-01
CVE-2024-37249 WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Contributor+ Broken Access Control vulnerability — Advanced Custom Fields PRO 4.3 Medium2024-11-01
CVE-2024-37095 WordPress Envira Photo Gallery plugin <= 1.8.7.3 - CSRF leading to notice dismissal vulnerability — Envira Photo Gallery 4.3 Medium2024-11-01
CVE-2024-37106 WordPress WishList Member X plugin < 3.26.7 - Unautenticated Plugin Settings Change Leading to Stored XSS vulnerability — WishList Member X 8.2 High2024-11-01
CVE-2024-37096 WordPress Popup box plugin <= 4.5.1 - Broken Access Control vulnerability — Popup box 4.3 Medium2024-11-01
CVE-2024-37119 WordPress Uncanny Automator Pro plugin < 5.3.0.1 - Unauthenticated License Settings Reset vulnerability — Uncanny Automator Pro 5.3 Medium2024-11-01
CVE-2024-37123 WordPress Ibtana – WordPress Website Builder plugin <= 1.2.3.3 - Broken Access Control vulnerability — Ibtana 5.3 Medium2024-11-01
CVE-2024-37203 WordPress Laybuy Payment Extension for WooCommerce plugin <= 5.3.9 - Broken Access Control vulnerability — Laybuy Payment Extension for WooCommerce 4.3 Medium2024-11-01
CVE-2024-37201 WordPress Woocommerce Customers Order History plugin <= 5.2.2 - Broken Access Control vulnerability — Woocommerce Customers Order History 4.3 Medium2024-11-01
CVE-2024-37207 WordPress Demo Awesome plugin <= 1.0.2 - Broken Access Control vulnerability — Demo Awesome 5.4 Medium2024-11-01
CVE-2024-37204 WordPress PropertyHive plugin <= 2.0.9 - Broken Access Control vulnerability — PropertyHive 4.3 Medium2024-11-01
CVE-2024-37214 WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Broken Access Control to XSS vulnerability — Ali2Woo Lite 6.5 Medium2024-11-01

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.