Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3206 Different Menu in Different Pages – Control Menu Visibility (All in One) <= 2.3.2 - Missing Authorization to Menu Duplication — Different Menu in Different Pages – Conditional Menu 4.3 Medium2024-05-02
CVE-2024-3520 Country State City Dropdown CF7 <= 2.7.1 - Missing Authorization — Country State City Dropdown CF7 4.3 Medium2024-05-02
CVE-2024-3585 Send PDF for Contact Form 7 <= 1.0.2.3 - Missing Authorization — Send PDF for Contact Form 7 5.3 Medium2024-05-02
CVE-2024-3581 MaxGalleria <= 6.4.2 - Missing Authorization — MaxGalleria 4.3 Medium2024-05-02
CVE-2024-1945 ARForms Form Builder <= 1.6.4 - Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion — Contact Form, Survey, Quiz & Popup Form Builder – ARForms 7.1 High2024-05-02
CVE-2024-33942 WordPress Google Typography plugin <= 1.1.2 - Broken Access Control vulnerability — Google Typography 4.3 Medium2024-05-02
CVE-2024-33944 WordPress WooCommerce AWeber Newsletter Subscription plugin <= 4.0.2 - Unauthenticated Access Token Change/Reset vulnerability — WooCommerce AWeber Newsletter Subscription 6.5 Medium2024-05-02
CVE-2024-33956 WordPress Custom WooCommerce Checkout Fields Editor plugin <= 1.3.0 - Broken Access Control vulnerability — Custom WooCommerce Checkout Fields Editor 4.3 Medium2024-05-02
CVE-2024-33938 WordPress Sliding Widgets plugin <= 1.5.0 - Broken Access Control to XSS vulnerability — Sliding Widgets 6.5 Medium2024-05-02
CVE-2024-3072 ACF Front End Editor <= 2.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Update — ACF Front End Editor 4.3 Medium2024-04-30
CVE-2024-1371 LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — LeadConnector 6.5 Medium2024-04-30
CVE-2023-48684 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect Cloud Agent 9.1AICriticalAI2024-04-29
CVE-2023-48683 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect Cloud Agent 9.1AICriticalAI2024-04-29
CVE-2024-33585 WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= 2.12.1 - Broken Access Control vulnerability — Payment Gateway Based Fees and Discounts for WooCommerce 4.3 Medium2024-04-29
CVE-2024-33586 WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerability — Photo Gallery by 10Web 5.3 Medium2024-04-29
CVE-2024-33587 WordPress Secure Copy Content Protection and Content Locking plugin <= 3.9.0 - Broken Access Control vulnerability — Secure Copy Content Protection and Content Locking 5.3 Medium2024-04-29
CVE-2024-33588 WordPress basepress plugin <= 2.16.1 - Broken Access Control vulnerability — Knowledge Base documentation & wiki plugin – BasePress 5.4 Medium2024-04-29
CVE-2024-33589 WordPress KB Support plugin <= 1.6.0 - Broken Access Control vulnerability — KB Support 6.5 Medium2024-04-29
CVE-2024-33591 WordPress Easy Accept Payments for PayPal plugin <= 4.9.10 - Broken Access Control vulnerability — Easy Accept Payments 7.5 High2024-04-29
CVE-2024-33593 WordPress Smart Forms plugin <= 2.6.91 - Broken Access Control vulnerability — Smart Forms 4.3 Medium2024-04-29
CVE-2024-33594 WordPress Leaky Paywall plugin <= 4.20.8 - Price Manipulation vulnerability — Leaky Paywall 7.5 High2024-04-29
CVE-2024-33595 WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on Duplicate Post vulnerability — Master Addons for Elementor 4.3 Medium2024-04-29
CVE-2024-33596 WordPress Five Star Restaurant Reservations plugin <= 2.6.16 - Broken Access Control vulnerability — Five Star Restaurant Reservations 5.3 Medium2024-04-29
CVE-2024-33597 WordPress SSU plugin <= 1.5.0 - Broken Access Control vulnerability — SSU 7.5 High2024-04-29
CVE-2024-33635 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Arbitrary Post/Page Deletion vulnerability — Piotnet Addons For Elementor Pro 7.5 High2024-04-29
CVE-2024-33636 WordPress WP Page Post Widget Clone plugin <= 1.0.1 - Broken Access Control vulnerability — WP Page Post Widget Clone 5.4 Medium2024-04-29
CVE-2024-33684 WordPress Save as PDF plugin by Pdfcrowd plugin <= 3.2.0 - Broken Access Control to Stored XSS vulnerability — Save as PDF plugin by Pdfcrowd 6.5 Medium2024-04-29
CVE-2024-33558 WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability — XStore Core 6.5 Medium2024-04-29
CVE-2024-33652 WordPress Client Dash plugin <= 2.2.1 - Broken Access Control vulnerability — Client Dash 5.3 Medium2024-04-29
CVE-2024-33566 WordPress OrderConvo plugin <= 12.4 - Unauthenticated API Access to Arbitrary File Upload vulnerability — OrderConvo 10.0 Critical2024-04-29

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.