Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6557 The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure — The Events Calendar 5.3 Medium2024-02-05
CVE-2023-4637 WPvivid <= 0.9.94 - Missing Authorization — WPvivid — Backup, Migration & Staging 4.3 Medium2024-02-05
CVE-2024-1121 Advanced Forms for ACF <= 1.9.3.2 - Missing Authorization to Unauthenticated Form Settings Export — Advanced Forms for ACF 5.3 Medium2024-02-05
CVE-2024-1072 Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage — Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode 8.2 High2024-02-05
CVE-2023-6959 Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification — Getwid – Gutenberg Blocks 4.3 Medium2024-02-05
CVE-2024-1177 WP Club Manager – WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update — WP Club Manager – WordPress Sports Club Plugin 5.3 Medium2024-02-05
CVE-2024-0835 Royal Elementor Kit <= 1.0.116 - Missing Authorization to Arbitrary Transient Update — Royal Elementor Kit 4.3 Medium2024-02-05
CVE-2023-6700 Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update — Cookie Information | Free GDPR Consent Solution 8.8 High2024-02-05
CVE-2024-0372 Views for WPForms <= 3.2.2 - Missing Authorization via get_form_fields — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium2024-02-05
CVE-2023-6985 10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation — 10Web AI Assistant – AI content writing assistant 6.5 Medium2024-02-05
CVE-2024-0791 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Missing Authorization — WOLF – WordPress Posts Bulk Editor and Manager Professional 4.3 Medium2024-02-05
CVE-2024-0869 Instant Images <= 6.1.0 - Authenticated (Author+) Arbitrary Options Update — Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy 8.8 High2024-02-05
CVE-2024-0797 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Missing Authorization — Active Products Tables for WooCommerce. Use constructor to create tables 4.3 Medium2024-02-05
CVE-2023-47148 IBM Storage Protect Plus Server information disclosure — Storage Protect Plus Server 5.3 Medium2024-02-02
CVE-2024-1047 ThemeIsle SDK <= Various Versions - Missing Authorization — Menu Icons by ThemeIsle 5.3 Medium2024-02-02
CVE-2024-1129 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred() — NEX-Forms – Ultimate Forms Plugin for WordPress 5.3 Medium2024-02-01
CVE-2024-1130 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read() — NEX-Forms – Ultimate Forms Plugin for WordPress 5.3 Medium2024-02-01
CVE-2024-0907 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via restore_records() — NEX-Forms – Ultimate Forms Plugin for WordPress 5.3 Medium2024-02-01
CVE-2024-0836 WordPress Review & Structure Data Schema Plugin – Review Schema <= 2.1.14 - Missing Authorization to Arbitrary Review Update — Review Schema – Review & Structure Data Schema Plugin 4.3 Medium2024-01-31
CVE-2023-22836 In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name from the default value, the renamed value may be visible to the rest of the stack’s tenants. — com.palantir.skywise:guardian 3.5 Low2024-01-29
CVE-2023-1705 Forcepoint One SmartEdge Agent 安全漏洞 — F|One SmartEdge Agent 8.4 High2024-01-29
CVE-2023-5612 Missing Authorization in GitLab — GitLab 5.3 Medium2024-01-26
CVE-2024-21630 Zulip non-admins can invite new users to streams they would not otherwise be able to add existing users to — zulip 4.3 Medium2024-01-25
CVE-2024-0617 Category Discount Woocommerce <= 4.12 - Missing Authorization via wpcd_save_discount() — Simple Discount Rules for Woocommerce 5.3 Medium2024-01-25
CVE-2023-50944 Apache Airflow: Bypass permission verification to read code of other dags — Apache Airflow 6.5 -2024-01-24
CVE-2024-0679 ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation — ColorMag 6.5 Medium2024-01-20
CVE-2022-42884 WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control — WIP Custom Login 5.4 Medium2024-01-17
CVE-2022-41790 WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control — WP Time Slots Booking Form 4.3 Medium2024-01-17
CVE-2022-41786 WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control — WP Job Portal – A Complete Job Board 5.4 Medium2024-01-17
CVE-2022-41695 WordPress Traffic Manager Plugin <= 1.4.5 is vulnerable to Broken Access Control — Traffic Manager 5.4 Medium2024-01-17

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.