Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-23875 CrawlChat's Discord Bot has a Knowledge Permission vulnerability — crawlchat 3.5AILowAI2026-01-19
CVE-2026-23721 OpenProject users with "View Members" permission in any project can view all Group memberships — openproject 4.3 Medium2026-01-19
CVE-2025-14078 PAYGENT for WooCommerce <= 2.4.6 - Missing Authorization to Unauthenticated Payment Callback Manipulation — PAYGENT for WooCommerce 5.3 Medium2026-01-17
CVE-2025-12825 User Registration Using Contact Form 7 <= 2.5 - Authenticated (Subscriber+) Information Exposure — User Registration Using Contact Form 7 5.3 Medium2026-01-17
CVE-2025-14029 Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter — Community Events 5.3 Medium2026-01-17
CVE-2025-12168 Phrase TMS Integration for WordPress <= 4.7.5 - Missing Authorization to Authenticated (Subscriber+) Log Deletion — Phrase TMS Integration for WordPress 4.3 Medium2026-01-17
CVE-2025-14463 Payment Button for PayPal <= 1.2.3.41 - Missing Authorization to Unauthenticated Arbitrary Order Creation — Payment Button for PayPal 5.3 Medium2026-01-17
CVE-2026-0820 RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders — RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress 4.3 Medium2026-01-17
CVE-2025-14450 Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation — Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments 6.5 Medium2026-01-17
CVE-2025-14757 Cost Calculator Builder <= 3.6.9 - Missing Authorization to Unauthenticated Payment Status Bypass — Cost Calculator Builder 5.3 Medium2026-01-16
CVE-2026-1004 Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Essential Addons for Elementor – Popular Elementor Templates & Widgets 5.3 Medium2026-01-16
CVE-2026-1003 GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion — GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools 4.3 Medium2026-01-16
CVE-2026-1000 MailerLite - WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion — MailerLite – WooCommerce integration 6.5 Medium2026-01-16
CVE-2025-14384 All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure — All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic 4.3 Medium2026-01-16
CVE-2025-12641 Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion — Awesome Support – WordPress HelpDesk & Support Plugin 6.5 Medium2026-01-16
CVE-2025-14982 Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure — Booking Calendar 4.3 Medium2026-01-16
CVE-2025-64729 AVEVA Process Optimization Missing Authorization — Process Optimization 8.1 High2026-01-16
CVE-2021-47812 GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2) — GravCMS 9.8 Critical2026-01-15
CVE-2025-13859 AffiliateX 1.0.0 - 1.3.9.3 - Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings — AffiliateX – Amazon Affiliate Plugin 6.4 Medium2026-01-15
CVE-2025-12895 Kalium <= 3.29 - Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request — Kalium 3 | Creative WordPress & WooCommerce Theme 5.3 Medium2026-01-15
CVE-2025-14457 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion — Drag and Drop Multiple File Upload for Contact Form 7 3.7 Low2026-01-15
CVE-2025-15475 PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated Order Status Modification — PayHere Payment Gateway 5.3 Medium2026-01-14
CVE-2025-14173 Perfit WooCommerce <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion — Perfit WooCommerce 5.3 Medium2026-01-14
CVE-2025-15512 Aplazo Payment Gateway <= 1.4.3 - Missing Authorization to Unauthenticated Order Status Manipulation — Aplazo Payment Gateway 5.3 Medium2026-01-14
CVE-2025-14854 WP-CRM System – Manage Clients and Projects <= 3.4.5 - Missing Authorization to Authenticated (Subscriber+) CRM Data Exposure and Task Modification — WP-CRM System – Manage Clients and Projects 5.4 Medium2026-01-14
CVE-2025-14880 Netcash WooCommerce Payment Gateway <= 4.1.3 - Missing Authorization to Unauthenticated Order Status Modification — Netcash WooCommerce Payment Gateway 5.3 Medium2026-01-14
CVE-2026-0635 Responsive Accordion Slider <= 1.2.2 - Missing Authorization to Authenticated (Contributor+) Slider Update via 'resp_accordion_silder_save_images' — Responsive Accordion Slider 4.3 Medium2026-01-14
CVE-2025-14482 Crush.pics Image Optimizer <= 1.8.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update — Crush.pics Image Optimizer – Image Compression and Optimization 4.3 Medium2026-01-14
CVE-2025-68947 NSecsoft NSecKrnl process termination privilege escalation — NSecKrnl 4.7 Medium2026-01-13
CVE-2025-11669 Broken Access Control — ManageEngine PAM360 8.1 High2026-01-13

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.