Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6621 WP RSS Aggregator <= 4.23.11 - Missing Authorization to Authenticated (Subscriber+) Feed State Update — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging 4.3 Medium2024-07-16
CVE-2024-6579 Web and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification — Web and WooCommerce Addons for WPBakery Builder 4.3 Medium2024-07-16
CVE-2024-1937 Brizy – Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification — Brizy – Page Builder 7.1 High2024-07-16
CVE-2024-6465 WP Links Page <= 4.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Image Update — WP Links Page 4.3 Medium2024-07-13
CVE-2024-37202 WordPress Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter plugin <= 1.222.17 - Broken Access Control to XSS vulnerability — Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter 6.5 Medium2024-07-12
CVE-2024-37544 WordPress Get Better Reviews for WooCommerce plugin <= 4.0.6 - Broken Access Control vulnerability — Get Better Reviews for WooCommerce 4.3 Medium2024-07-12
CVE-2024-6392 Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Authenticated(Subscriber+) Missing Authorization to Plugin Settings Update — Image Optimizer, Resizer and CDN – Sirv 5.4 Medium2024-07-11
CVE-2024-39546 Junos OS Evolved: Local low-privilege user can gain root permissions leading to privilege escalation — Junos OS Evolved 7.3 High2024-07-11
CVE-2024-0619 Payflex Payment Gateway <= 2.5.0 - Missing Authorization to Order Status Update — Payflex Payment Gateway 5.3 Medium2024-07-11
CVE-2024-5677 Featured Image Generator <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Images Upload — Featured Image Generator 4.3 Medium2024-07-10
CVE-2024-21417 Windows Text Services Framework Elevation of Privilege Vulnerability — Windows 10 Version 1809 8.8 High2024-07-09
CVE-2024-5669 XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Happy WooCommerce FAQs – Ultimate Product FAQ Plugin 6.4 Medium2024-07-09
CVE-2024-6069 Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation — Pie Register – User Registration, Profiles & Content Restriction 8.8 High2024-07-09
CVE-2024-4102 Pricing Table <= 2.0.1 - Missing Authorization — Pricing Table 5.4 Medium2024-07-09
CVE-2024-5992 Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Unauthenticated Chatbot Settings Update — Cliengo – Chatbot 6.5 Medium2024-07-09
CVE-2024-5648 LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update — LearnDash LMS – Reports 5.4 Medium2024-07-09
CVE-2024-5856 Comment Images Reloaded <= 2.2.1 - Authenticated (Subscriber+) Arbitrary Media Deletion — Comment Images Reloaded 4.3 Medium2024-07-09
CVE-2024-5600 Happy SCSS Compiler - Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue 5.4 Medium2024-07-09
CVE-2024-3608 Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — PickPlugins Product Designer for WooCommerce 5.3 Medium2024-07-09
CVE-2024-5704 XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Happy WooCommerce FAQs – Ultimate Product FAQ Plugin 4.3 Medium2024-07-09
CVE-2024-6167 Just Custom Fields <= 3.3.2 - Missing Authorization via AJAX actions — Just Custom Fields 4.3 Medium2024-07-09
CVE-2024-5993 Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update — Cliengo – Chatbot 5.4 Medium2024-07-09
CVE-2024-6180 EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates — EventON – Events Calendar 7.2 High2024-07-09
CVE-2024-39596 [CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now — SAP Enable Now 4.3 Medium2024-07-09
CVE-2024-37172 [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management) — SAP S/4HANA Finance (Advanced Payment Management) 5.4 Medium2024-07-09
CVE-2024-37175 [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI) — SAP CRM WebClient UI 4.3 Medium2024-07-09
CVE-2024-39592 [CVE-2024-39592] Missing Authorization check in SAP PDCE — SAP PDCE 7.7 High2024-07-09
CVE-2024-5855 Media Hygiene <= 3.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion — Media Hygiene: Remove or Delete Unused Images and More! 4.3 Medium2024-07-09
CVE-2024-37542 WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability — Responsive Image Gallery, Gallery Album 5.4 Medium2024-07-06
CVE-2024-37903 Mastodon has improper authorship check on audience extension for existing posts — mastodon 8.2 High2024-07-05

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.