Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-41016 Multiple vulnerabilities in DFUSION by Davantis — DFUSION 5.3AIMediumAI2025-11-24
CVE-2025-13318 Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter — Booking Calendar Contact Form 5.3 Medium2025-11-22
CVE-2025-13136 GSheetConnector For Ninja Forms <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) System Information Exposure — GSheetConnector For Ninja Forms 4.3 Medium2025-11-22
CVE-2025-12877 IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — IDonate – Blood Donation, Request And Donor Management System 5.3 Medium2025-11-22
CVE-2025-13384 CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment Confirmation — CP Contact Form with PayPal 7.5 High2025-11-22
CVE-2025-13317 Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter — Appointment Booking Calendar 5.3 Medium2025-11-22
CVE-2025-66112 WordPress Accessibility Toolkit by WebYes plugin <= 2.0.4 - Broken Access Control vulnerability — Accessibility Toolkit by WebYes 4.3 Medium2025-11-21
CVE-2025-66114 WordPress Show Variations as Single Products Woocommerce plugin <= 2.0 - Broken Access Control vulnerability — Show Variations as Single Products Woocommerce 5.3 Medium2025-11-21
CVE-2025-66113 WordPress Better Chat Support for Messenger plugin <= 1.2.18 - Broken Access Control vulnerability — Better Chat Support for Messenger 5.3 Medium2025-11-21
CVE-2025-66110 WordPress Tiktok Feed plugin <= 1.0.23 - Broken Access Control vulnerability — Tiktok Feed 5.3 Medium2025-11-21
CVE-2025-66108 WordPress TNC Toolbox: Web Performance plugin <= 2.0.4 - Broken Access Control vulnerability — TNC Toolbox: Web Performance 4.3 Medium2025-11-21
CVE-2025-66109 WordPress Cart Weight for WooCommerce plugin <= 1.9.11 - Broken Access Control vulnerability — Cart Weight for WooCommerce 5.3 Medium2025-11-21
CVE-2025-66106 WordPress Featured Post Creative plugin <= 1.5.5 - Broken Access Control vulnerability — Featured Post Creative 4.3 Medium2025-11-21
CVE-2025-66107 WordPress Subscriptions & Memberships for PayPal plugin <= 1.1.7 - Broken Access Control vulnerability — Subscriptions & Memberships for PayPal 5.3 Medium2025-11-21
CVE-2025-66101 WordPress CBX Bookmark & Favorite plugin <= 2.0.1 - Broken Access Control vulnerability — CBX Bookmark & Favorite 4.3 Medium2025-11-21
CVE-2025-66099 WordPress Chat Help plugin <= 3.1.3 - Broken Access Control vulnerability — Chat Help 5.3 Medium2025-11-21
CVE-2025-66096 WordPress Table Block by Tableberg plugin <= 0.6.9 - Broken Access Control vulnerability — Table Block by Tableberg 4.3 Medium2025-11-21
CVE-2025-66087 WordPress PropertyHive plugin <= 2.1.12 - Broken Access Control vulnerability — PropertyHive 4.3 Medium2025-11-21
CVE-2025-66089 WordPress Product Feed for WooCommerce plugin <= 2.3.1 - Broken Access Control vulnerability — Product Feed for WooCommerce 4.3 Medium2025-11-21
CVE-2025-66083 WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerability — WpEvently 5.3 Medium2025-11-21
CVE-2025-66082 WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerability — WpEvently 5.3 Medium2025-11-21
CVE-2025-66085 WordPress Arconix Shortcodes plugin <= 2.1.18 - Broken Access Control vulnerability — Arconix Shortcodes 4.3 Medium2025-11-21
CVE-2025-66084 WordPress FluentCommunity plugin <= 2.0.0 - Broken Access Control vulnerability — FluentCommunity 4.3 Medium2025-11-21
CVE-2025-66086 WordPress SMS Alert Order Notifications plugin <= 3.8.8 - Broken Access Control vulnerability — SMS Alert Order Notifications 5.3 Medium2025-11-21
CVE-2025-66075 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.0.3 - Broken Access Control vulnerability — WP Cookie Notice for GDPR, CCPA & ePrivacy Consent 4.3 Medium2025-11-21
CVE-2025-66077 WordPress Legal Pages plugin <= 1.4.6 - Broken Access Control vulnerability — Legal Pages 5.3 Medium2025-11-21
CVE-2025-66079 WordPress Gutenverse Form plugin <= 2.2.0 - Broken Access Control vulnerability — Gutenverse Form 6.5 Medium2025-11-21
CVE-2025-66065 WordPress Gutenverse plugin <= 3.2.1 - Broken Access Control vulnerability — Gutenverse 6.5 Medium2025-11-21
CVE-2025-66071 WordPress Custom Order Numbers for WooCommerce plugin <= 1.11.0 - Broken Access Control vulnerability — Custom Order Numbers for WooCommerce 5.3 Medium2025-11-21
CVE-2025-66069 WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerability — PPOM for WooCommerce 4.3 Medium2025-11-21

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.