Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3609 ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization — ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema 4.3 Medium2024-05-16
CVE-2024-2619 Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Author+) HTML Injection — Ultimate Addons for Elementor 5.0 Medium2024-05-16
CVE-2024-4352 Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection — Tutor LMS Pro 8.8 High2024-05-16
CVE-2024-4222 Tutor LMS Pro <= 2.7.0 - Missing Authorization — Tutor LMS Pro 7.3 High2024-05-16
CVE-2024-4223 Tutor LMS <= 2.7.0 - Missing Authorization — Tutor LMS – eLearning and online course solution 9.8 Critical2024-05-16
CVE-2024-3750 Visualizer: Tables and Charts Manager for WordPress <= 3.10.15 - Missing Authorization to Arbitrary SQL Execution — Visualizer: Tables and Charts Manager for WordPress 8.8 High2024-05-16
CVE-2024-4010 Email Subscribers by Icegram Express <= 5.7.19 - Missing Authorization in handle_ajax_request — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress 8.8 High2024-05-15
CVE-2024-4199 Bulk Posts Editing For WordPress <= 4.2.3 - Authenticated (Subscriber+) Missing Authorization — WPBULKiT – Bulk Edit WordPress Posts & Pages 4.3 Medium2024-05-15
CVE-2024-27939 Siemens RUGGEDCOM CROSSBOW 安全漏洞 — RUGGEDCOM CROSSBOW 9.8 Critical2024-05-14
CVE-2024-4445 WP Compress – Image Optimizer [All-In-One] <= 6.20.01 - Missing Authorization — WP Compress – Instant Performance & Speed Optimization 6.5 Medium2024-05-14
CVE-2024-4138 Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules) — SAP S/4 HANA (Manage Bank Statement Reprocessing Rules) 4.3 Medium2024-05-14
CVE-2024-4139 Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules) — SAP S/4 HANA (Manage Bank Statement Reprocessing Rules) 4.3 Medium2024-05-14
CVE-2024-33000 Missing Authorization check in SAP Bank Account Management — SAP Bank Account Management 3.5 Low2024-05-14
CVE-2024-32731 Missing Authorization check in SAP My Travel Requests — SAP My Travel Requests 5.5 Medium2024-05-14
CVE-2024-32776 WordPress AppPresser plugin <= 4.3.0 - Broken Access Control vulnerability — AppPresser 6.5 Medium2024-05-10
CVE-2024-4280 White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset — White Label CMS 5.3 Medium2024-05-10
CVE-2024-3915 Swift Framework <= 2.7.31 - Missing Authorization to Unauthenticated Arbitrary Content Update — Swift Framework 5.3 Medium2024-05-09
CVE-2024-1229 SimpleShop <= 2.10.2 - Missing Authorization — SimpleShop 5.3 Medium2024-05-09
CVE-2023-6327 ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 5.3 Medium2024-05-09
CVE-2024-4317 PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks — PostgreSQL 3.1 Low2024-05-09
CVE-2024-32712 WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability — Podlove Podcast Publisher 7.5 High2024-05-09
CVE-2024-32717 WordPress SchedulePress plugin <= 5.0.8 - Broken Access Control vulnerability — SchedulePress 6.5 Medium2024-05-09
CVE-2024-32719 WordPress WP Club Manager plugin <= 2.2.11 - Broken Access Control vulnerability — WP Club Manager 5.3 Medium2024-05-09
CVE-2024-32724 WordPress SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy plugin <= 2.1.1 - Arbitrary Content Deletion vulnerability — Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy 7.5 High2024-05-09
CVE-2024-33573 WordPress EPROLO Dropshipping plugin <= 1.7.1 - Broken Access Control vulnerability — EPROLO Dropshipping 4.3 Medium2024-05-08
CVE-2024-33574 WordPress Vitepos plugin <= 3.0.1 - Broken Access Control vulnerability — Vitepos 4.3 Medium2024-05-08
CVE-2024-24833 WordPress Happy Addons for Elementor plugin <= 3.10.1 - Broken Access Control on Post Clone vulnerability — Happy Addons for Elementor 4.3 Medium2024-05-08
CVE-2024-31270 WordPress ARForms Form Builder plugin <= 1.6.1 - Broken Access Control vulnerability — ARForms Form Builder 7.6 High2024-05-08
CVE-2024-30459 WordPress AI WP Writer plugin <= 3.6.5 - Broken Access Control vulnerability — AI WP Writer 5.3 Medium2024-05-08
CVE-2024-4233 Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares — Print Invoice & Delivery Notes for WooCommerce 4.3 Medium2024-05-08

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.