Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5530

5530 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-24984 WordPress Visual Link Preview plugin <= 2.2.9 - Broken Access Control vulnerability — Visual Link Preview 6.5 Medium2026-02-03
CVE-2026-24967 WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability — Amelia 5.3 Medium2026-02-03
CVE-2026-24985 WordPress WP Forms Signature Contract Add-On plugin <= 1.8.2 - Broken Access Control to Notice Dismissal vulnerability — WP Forms Signature Contract Add-On 4.3 Medium2026-02-03
CVE-2026-24965 WordPress Contest Gallery plugin <= 28.1.1 - Broken Access Control vulnerability — Contest Gallery 4.3 Medium2026-02-03
CVE-2026-24957 WordPress Strong Testimonials plugin <= 3.2.20 - Broken Access Control vulnerability — Strong Testimonials 6.5 Medium2026-02-03
CVE-2026-24947 WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability — LA-Studio Element Kit for Elementor 4.3 Medium2026-02-03
CVE-2026-24951 WordPress myCred plugin <= 2.9.7.3 - Broken Access Control vulnerability — myCred 4.3 Medium2026-02-03
CVE-2026-24939 WordPress Modula Image Gallery plugin <= 2.13.6 - Broken Access Control vulnerability — Modula Image Gallery 4.3 Medium2026-02-03
CVE-2026-24945 WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.34 - Broken Access Control vulnerability — Ultimate Addons for Contact Form 7 5.3 Medium2026-02-03
CVE-2026-24940 WordPress Travelfic Toolkit plugin <= 1.3.3 - Broken Access Control vulnerability — Travelfic Toolkit 4.3 Medium2026-02-03
CVE-2026-1751 Missing Authorization in GitLab — GitLab 3.1 Low2026-02-02
CVE-2025-13348 ASUS Business Manager 安全漏洞 — ASUS Business Manager 5.5AIMediumAI2026-02-02
CVE-2026-1734 Zhong Bang CRMEB crontab Endpoint CrontabController.php authorization — CRMEB 5.3 Medium2026-02-01
CVE-2026-1431 Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure — Booking Calendar 5.3 Medium2026-01-31
CVE-2025-15510 NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure — NEX-Forms – Ultimate Forms Plugin for WordPress 5.3 Medium2026-01-31
CVE-2026-21865 Discourse topic conversion permission vulnerability for moderators — discourse 6.5 Medium2026-01-28
CVE-2025-68479 Discourse subscriptions are susceptible to takeover — discourse 7.1 High2026-01-28
CVE-2026-1280 Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter — Frontend File Manager Plugin 7.5 High2026-01-28
CVE-2025-14386 Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization 2.4.4 - 2.5.12 - Missing Authorization to Authenticated (Subscriber+) Authentication Bypass via Account Takeover — Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization 8.8 High2026-01-28
CVE-2025-15511 Rupantorpay <= 2.0.0 - Missing Authorization to Unauthenticated Order Status Modification — Rupantorpay 5.3 Medium2026-01-28
CVE-2026-1054 RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 5.3 Medium2026-01-28
CVE-2026-0832 New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure — New User Approve 7.3 High2026-01-28
CVE-2026-1310 Simple calendar for Elementor <= 1.6.6 - Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion — Simple calendar for Elementor 5.3 Medium2026-01-28
CVE-2026-0825 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export — Database for Contact Form 7, WPforms, Elementor forms 5.3 Medium2026-01-28
CVE-2026-1298 Easy Replace Image <= 3.5.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement — Easy Replace Image 4.3 Medium2026-01-28
CVE-2025-14971 Link Invoice Payment for WooCommerce <= 2.8.0 - Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation — Link Invoice Payment for WooCommerce 5.3 Medium2026-01-27
CVE-2026-23683 Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation) — SAP Fiori App (Intercompany Balance Reconciliation) 4.3 Medium2026-01-27
CVE-2026-0593 WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification — WP Go Maps (formerly WP Google Maps) 5.3 Medium2026-01-24
CVE-2026-0687 Meta-box GalleryMeta <= 3.0.1 - Missing Authorization to Authenticated (Author+) Gallery Management — Meta-box GalleryMeta 4.3 Medium2026-01-24
CVE-2025-15516 All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update — All-in-One Video Gallery 4.3 Medium2026-01-24

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5530 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.