Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-41619 WordPress Image Zoom Plugin <= 1.8.8 is vulnerable to Broken Access Control — Image Zoom 5.4 Medium2024-01-17
CVE-2022-40702 WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control — Advanced Local Pickup for WooCommerce 5.4 Medium2024-01-17
CVE-2023-23882 WordPress Ultimate Addons for Beaver Builder – Lite Plugin <= 1.5.5 is vulnerable to Broken Access Control — Ultimate Addons for Beaver Builder – Lite 4.3 Medium2024-01-17
CVE-2023-23896 WordPress URL Shortener by MyThemeShop Plugin <= 1.0.17 is vulnerable to Broken Access Control — URL Shortener by MyThemeShop 5.4 Medium2024-01-17
CVE-2023-34379 WordPress Cart2Cart: Magento to WooCommerce Migration Plugin <= 2.0.0 is vulnerable to Broken Access Control — Cart2Cart: Magento to WooCommerce Migration 5.4 Medium2024-01-17
CVE-2022-40203 WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control — Advanced Dynamic Pricing for WooCommerce 6.3 Medium2024-01-17
CVE-2022-38141 WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control — Sales Report Email for WooCommerce 4.3 Medium2024-01-17
CVE-2022-36418 WordPress HREFLANG Tags Lite Plugin <= 2.0.0 is vulnerable to Broken Authentication — HREFLANG Tags Lite 6.5 Medium2024-01-17
CVE-2023-6955 Missing Authorization in GitLab — GitLab 6.6 Medium2024-01-12
CVE-2023-6554 Missing authorisation in TCExam — TCExam 6.5AIMediumAI2024-01-11
CVE-2023-6598 SpeedyCache <= 1.1.3 - Missing Authorization to Plugin Options Update — SpeedyCache – Cache, Optimization, Performance 4.3 Medium2024-01-11
CVE-2023-6751 Hostinger <= 1.9.7 - Missing Authorization to Maintenance Mode Activation — Hostinger Tools 7.3 High2024-01-11
CVE-2023-6638 GTG Product Feed for Shopping <= 1.2.4 - Missing Authorization to Unauthenticated Plugin Settings Update — GG Woo Feed for WooCommerce Shopping Feed on Google and Other Channels 6.5 Medium2024-01-11
CVE-2023-7019 LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorization — LightStart – Maintenance Mode, Coming Soon and Landing Page Builder 4.3 Medium2024-01-11
CVE-2023-6637 CAOS | Host Google Analytics Locally <= 4.7.14 - Missing Authorization to Unauthenticated Plugin Settings Update — CAOS | Host Google Analytics Locally 6.5 Medium2024-01-11
CVE-2023-6369 Export WP Page to Static HTML/CSS <= 2.1.9 - Missing Authorization via Multiple AJAX Actions — Export WordPress Pages to Static HTML & PDF — Static Site Export 5.4 Medium2024-01-11
CVE-2023-6742 Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_images — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More 4.3 Medium2024-01-11
CVE-2023-6855 Paid Memberships Pro <= 2.12.5 - Missing Authorization via API — Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions 5.3 Medium2024-01-11
CVE-2023-6883 Easy Social Feed <= 6.5.2 - Missing Authorization to Settings Modification — Easy Social Feed – Social Photos Gallery and Post Feed for WordPress 4.3 Medium2024-01-11
CVE-2023-6158 EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta — EventON – Events Calendar 6.5 Medium2024-01-10
CVE-2023-48247 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001) 5.3 Medium2024-01-10
CVE-2023-48245 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001) 6.5 Medium2024-01-10
CVE-2022-36352 WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control — ProfileGrid – User Profiles, Memberships, Groups and Communities 6.3 Medium2024-01-08
CVE-2022-34344 WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control — Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More 5.4 Medium2024-01-08
CVE-2023-6798 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 5.4 Medium2024-01-06
CVE-2024-0201 Product Expiry for WooCommerce <= 2.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update — Product Expiry for WooCommerce 5.4 Medium2024-01-03
CVE-2023-7068 WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels 4.3 Medium2024-01-03
CVE-2023-6600 OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 5.7.9 - Missing Authorization to Unauthenticated Directory Deletion and Cross-Site Scripting — OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. 8.6 High2024-01-03
CVE-2023-4468 Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization — Trio 8500 4.3 Medium2023-12-29
CVE-2023-22676 WordPress Advanced Custom Fields: Image Crop Add-on Plugin <= 1.4.12 is vulnerable to Broken Access Control — Anders Thorborg 3.1 Low2023-12-29

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.