Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-66058 WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability — Post Grid and Gutenberg Blocks 6.5 Medium2025-12-18
CVE-2025-7047 Missing Authorization in Utarit Informatics' SoliClub — SoliClub 4.3 Medium2025-12-18
CVE-2025-14618 Sweet Energy Efficiency <= 1.0.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Graph Deletion — Sweet Energy Efficiency 4.3 Medium2025-12-18
CVE-2025-40602 SonicWALL SMA1000 安全漏洞 — SMA1000 7.8AIHighAI2025-12-18
CVE-2025-14364 Demo Importer Plus <= 2.0.8 - Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation — Demo Importer Plus 8.8 High2025-12-18
CVE-2025-66104 WordPress Offload, AI & Optimize with Cloudflare Images plugin <= 1.9.5 - Broken Access Control vulnerability — Offload, AI & Optimize with Cloudflare Images 6.5 Medium2025-12-18
CVE-2025-66117 WordPress Easy Form plugin <= 2.7.8 - Broken Access Control vulnerability — Easy Form 7.5 High2025-12-18
CVE-2025-66100 WordPress RestroPress plugin <= 3.2.3.5 - Broken Access Control vulnerability — RestroPress 6.5 Medium2025-12-18
CVE-2025-66088 WordPress PropertyHive plugin <= 2.1.12 - Broken Access Control vulnerability — PropertyHive 7.5 High2025-12-18
CVE-2025-66068 WordPress InstaWP Connect plugin <= 0.1.1.9 - Broken Access Control vulnerability — InstaWP Connect 6.5 Medium2025-12-18
CVE-2025-66070 WordPress wpForo Forum plugin <= 2.4.10 - Broken Access Control vulnerability — wpForo Forum 7.5 High2025-12-18
CVE-2025-66054 WordPress LearnPress plugin <= 4.2.9.4 - Broken Access Control vulnerability — LearnPress 7.5 High2025-12-18
CVE-2025-64378 WordPress ListingPro theme < 2.9.10 - Broken Access Control vulnerability — ListingPro 7.1 High2025-12-18
CVE-2025-64375 WordPress WP Social Ninja plugin <= 3.20.1 - Broken Access Control vulnerability — WP Social Ninja 6.5 Medium2025-12-18
CVE-2025-64268 WordPress Timetics plugin <= 1.0.44 - Broken Access Control vulnerability — Timetics 7.5 High2025-12-18
CVE-2025-64273 WordPress Email marketing for WordPress by GetResponse Official plugin <= 1.5.3 - Broken Access Control vulnerability — Email marketing for WordPress by GetResponse Official 6.5 Medium2025-12-18
CVE-2025-64222 WordPress WooCommerce Recover Abandoned Cart plugin <= 24.6.0 - Arbitrary Content Deletion vulnerability — WooCommerce Recover Abandoned Cart 7.5 High2025-12-18
CVE-2025-64209 WordPress Masterstudy theme < 4.8.122 - Broken Access Control vulnerability — Masterstudy 7.5 High2025-12-18
CVE-2025-64214 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Arbitrary Content Deletion vulnerability — MasterStudy LMS Pro 7.5 High2025-12-18
CVE-2025-64192 WordPress XStore theme < 9.6 - Broken Access Control vulnerability — XStore 6.3 Medium2025-12-18
CVE-2025-63039 WordPress ListingPro theme <= 2.9.9 - Broken Access Control vulnerability — ListingPro 6.5 Medium2025-12-18
CVE-2025-60088 WordPress WebinarIgnition plugin <= 4.06.04 - Broken Access Control vulnerability — WebinarIgnition 6.5 Medium2025-12-18
CVE-2025-60086 WordPress WP Voting Contest plugin <= 5.8 - Broken Access Control vulnerability — WP Voting Contest 7.5 High2025-12-18
CVE-2025-60079 WordPress Parallax Section block plugin <= 1.0.9 - Broken Authentication vulnerability — Parallax Section block 7.1 High2025-12-18
CVE-2025-60077 WordPress YayPricing plugin <= 3.5.3 - Broken Access Control vulnerability — YayPricing 7.5 High2025-12-18
CVE-2025-60045 WordPress IDonatePro plugin <= 2.1.11 - Broken Access Control vulnerability — IDonatePro 7.5 High2025-12-18
CVE-2025-58938 WordPress IDonatePro plugin <= 2.1.9 - Broken Access Control vulnerability — IDonatePro 7.5 High2025-12-18
CVE-2025-58877 WordPress Javo Core plugin <= 3.0.0.529 - Arbitrary Content Deletion vulnerability — Javo Core 7.5 High2025-12-18
CVE-2025-54745 WordPress miniOrange's Google Authenticator Plugin <= 6.1.1 - Broken Access Control Vulnerability — miniOrange's Google Authenticator 6.5 Medium2025-12-18
CVE-2025-54743 WordPress Download After Email Plugin 2.1.5-2.1.6 - Other Vulnerability Type Vulnerability — Download After Email 5.8 Medium2025-12-18

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.