Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-25457 WordPress Slider Carousel – Responsive Image Slider plugin <=1.5.1 - Broken Access Control vulnerability — Slider Carousel – Responsive Image Slider 5.3 Medium2024-05-03
CVE-2023-44472 WordPress Unyson plugin <= 2.7.28 - Broken Access Control vulnerability — Unyson 4.3 Medium2024-05-03
CVE-2024-33941 WordPress iPanorama 360 plugin <= 1.8.1 - Broken Access Control vulnerability — iPanorama 360 WordPress Virtual Tour Builder 5.3 Medium2024-05-03
CVE-2023-38102 NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability — ProSAFE Network Management System 9.8 -2024-05-03
CVE-2024-3601 Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration — Poll Maker – Versus Polls, Anonymous Polls, Image Polls 5.3 Medium2024-05-02
CVE-2024-3553 Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update — Tutor LMS – eLearning and online course solution 6.5 Medium2024-05-02
CVE-2024-3936 The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization — The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid 4.3 Medium2024-05-02
CVE-2024-3897 Popup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups 5.3 Medium2024-05-02
CVE-2024-1716 Admin Bar Remover <= 1.0.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Admin Bar Editor – Toolbar Customization with User Role based access & Custom menus 4.3 Medium2024-05-02
CVE-2024-3607 PropertyHive <= 2.0.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion — Property Hive 4.3 Medium2024-05-02
CVE-2024-2417 User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 8.8 High2024-05-02
CVE-2024-3233 Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation — Ivory Search – WordPress Search Plugin 4.3 Medium2024-05-02
CVE-2024-3606 ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization — ProfileGrid – User Profiles, Groups and Communities 4.3 Medium2024-05-02
CVE-2024-0629 2Checkout Payment Gateway for WooCommerce <= 6.2 - Missing Authorization via sniff_ins — 2Checkout Payment Gateway for WooCommerce 5.3 Medium2024-05-02
CVE-2024-2797 MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization — MailerLite – Signup forms (official) 5.3 Medium2024-05-02
CVE-2024-3287 SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.2 - Missing Authorization — SmartCrawl SEO checker, analyzer & optimizer 5.3 Medium2024-05-02
CVE-2024-0908 Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure — Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters 5.3 Medium2024-05-02
CVE-2024-3312 Easy Custom Auto Excerpt <= 2.4.12 - Sensitive Information Exposure — Easy Custom Auto Excerpt 5.3 Medium2024-05-02
CVE-2024-2109 Booster Extension <= 1.2.0 - Basic Information Exposure via booster_extension_authorbox_shortcode_display — Booster Extension 5.3 Medium2024-05-02
CVE-2024-3295 User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 6.5 Medium2024-05-02
CVE-2023-7067 ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 4.3 Medium2024-05-02
CVE-2024-1677 Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.6 - Improper Authorization — Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce 6.3 Medium2024-05-02
CVE-2024-2043 EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.7 - Missing Authorization to Sensitive Information Exposure — EleForms – All In One Form Integration including DB for Elementor 5.3 Medium2024-05-02
CVE-2024-1688 Woo Total Sales <= 3.1.4 - Missing Authorization to Unauthenticated Sales Report Retrieval — Woo Total Sales 5.3 Medium2024-05-02
CVE-2024-3942 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization — MasterStudy LMS WordPress Plugin – for Online Courses and Education 6.3 Medium2024-05-02
CVE-2024-3275 eRoom – Zoom Meetings & Webinar <= 1.4.18 - Missing Authorization to Information Exposure — eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams 4.3 Medium2024-05-02
CVE-2024-3599 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent 5.3 Medium2024-05-02
CVE-2024-3071 ACF On-The-Go <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Update — ACF On-The-Go 4.3 Medium2024-05-02
CVE-2024-3895 WP Datepicker <= 2.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update — WP Datepicker 8.8 High2024-05-02
CVE-2024-3546 WordPress Backup & Migration <= 1.4.8 - Missing Authorization to Directory Traversal — WebToffee WP Backup and Migration 4.3 Medium2024-05-02

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.