Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-9364 SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion — SendGrid for WordPress 4.3 Medium2024-10-18
CVE-2024-9361 Bulk images optimizer: Resize, optimize, convert to webp, rename ... <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Options Update — Bulk images optimizer: Resize, optimize, convert to webp, rename … 4.3 Medium2024-10-18
CVE-2024-45461 Apache CloudStack Quota plugin: Access checks not enforced in Quota — Apache CloudStack Quota plugin 5.7 Medium2024-10-16
CVE-2020-36840 Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization — Timetable and Event Schedule by MotoPress 7.3 High2024-10-16
CVE-2023-7294 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_profile' — Paytium: Mollie payment forms & donations 7.1 High2024-10-16
CVE-2023-7293 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_mollie_account_details' — Paytium: Mollie payment forms & donations 4.3 Medium2024-10-16
CVE-2023-7292 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_notice_dismiss' — Paytium: Mollie payment forms & donations 4.3 Medium2024-10-16
CVE-2023-7291 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_account' — Paytium: Mollie payment forms & donations 7.1 High2024-10-16
CVE-2021-4445 Premium Addons for Elementor <= 4.5.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update — Premium Addons for Elementor – Powerful Elementor Templates & Widgets 6.5 Medium2024-10-16
CVE-2019-25214 ShopWP <= 2.0.4 - Missing Authorization to Stored Cross-Site Scripting — ShopWP 7.2 High2024-10-16
CVE-2021-4447 Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation — Essential Addons for Elementor – Popular Elementor Templates & Widgets 8.8 High2024-10-16
CVE-2020-36833 Indeed Membership Pro 7.3 - 8.6 - Missing Authorization Checks — Indeed Membership Pro 6.3 Medium2024-10-16
CVE-2023-7290 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_for_verified_profiles' — Paytium: Mollie payment forms & donations 4.3 Medium2024-10-16
CVE-2023-7289 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_sw_save_api_keys' — Paytium: Mollie payment forms & donations 5.4 Medium2024-10-16
CVE-2018-25105 File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download — File Manager 9.8 Critical2024-10-16
CVE-2022-4972 Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export — Download Monitor 7.5 High2024-10-16
CVE-2020-36837 ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset — ThemeGrill Demo Importer 9.9 Critical2024-10-16
CVE-2019-25215 ARI-Adminer <= 1.1.14 - Missing Authorization and No Direct File Access Restrictions — ARI Adminer – WordPress Database Manager 7.3 High2024-10-16
CVE-2019-25217 SiteGround Optimizer <= 5.0.12 - Missing Authorization — Speed Optimizer – The All-In-One Performance-Boosting Plugin 9.8 Critical2024-10-16
CVE-2021-4448 Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization — Kaswara Modern VC Addons 7.3 High2024-10-16
CVE-2022-4974 Freemius SDK <= 2.4.2 - Missing Authorization Checks — YASR – Yet Another Star Rating Plugin for WordPress 6.3 Medium2024-10-16
CVE-2020-36834 Discount Rules for WooCommerce <= 2.0.2 - Missing Authorization — Discount Rules for WooCommerce 6.3 Medium2024-10-16
CVE-2021-4444 Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization — Product Filter for WooCommerce by WBW 7.3 High2024-10-16
CVE-2021-4446 Essential Addons for Elementor <= 4.6.4 - Missing Authorization — Essential Addons for Elementor – Popular Elementor Templates & Widgets 6.3 Medium2024-10-16
CVE-2023-7288 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'update_profile_preference' — Paytium: Mollie payment forms & donations 5.4 Medium2024-10-16
CVE-2023-7287 Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription' — Paytium: Mollie payment forms & donations 5.4 Medium2024-10-16
CVE-2024-9891 Multiline files upload for contact form 7 <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation — MultiLine Files for Contact Form 7 4.3 Medium2024-10-16
CVE-2024-38190 Power Platform Information Disclosure Vulnerability — Microsoft Power Platform 8.6 High2024-10-15
CVE-2024-45732 Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app — Splunk Enterprise 7.1 High2024-10-14
CVE-2024-9756 Order Attachments for WooCommerce 2.0 - 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload — Order Attachments for WooCommerce 4.3 Medium2024-10-12

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.