Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13654 ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Deletion — ZoxPress - The All-In-One WordPress News Theme 8.1 High2025-02-12
CVE-2024-13653 ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update — ZoxPress - The All-In-One WordPress News Theme 8.8 High2025-02-12
CVE-2024-12164 WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset — WPSyncSheets For WPForms – Google Sheets Connector for WPForms & Real‑Time Data Export 4.3 Medium2025-02-12
CVE-2024-13800 Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update — ConvertPlus 8.1 High2025-02-12
CVE-2024-13769 Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Puzzles | WP Magazine / Review with Store WordPress Theme + RTL 6.4 Medium2025-02-12
CVE-2024-13541 aDirectory – WordPress Directory Listing Plugin <= 2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion — aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory 4.3 Medium2025-02-12
CVE-2024-13554 The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation — The Ultimate WordPress Toolkit – WP Extended 5.3 Medium2025-02-12
CVE-2024-13643 Zox News <= 3.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Modification — Zox News - Professional WordPress News & Magazine Theme 8.8 High2025-02-11
CVE-2025-25241 Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests) — SAP Fiori Apps Reference Library (My Overtime Requests) 5.4 Medium2025-02-11
CVE-2025-23190 Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI) — SAP NetWeaver and ABAP platform (ST-PI) 4.3 Medium2025-02-11
CVE-2025-23189 Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) — SAP NetWeaver and ABAP Platform (SDCCN) 4.3 Medium2025-02-11
CVE-2025-23187 Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) — SAP NetWeaver and ABAP Platform (SDCCN) 5.3 Medium2025-02-11
CVE-2025-25167 WordPress BookPress – For Book Authors Plugin <= 1.2.7 - Broken Access Control vulnerability — BookPress – For Book Authors 8.2 High2025-02-07
CVE-2025-25120 WordPress Slide Banners plugin <= 1.3 - Broken Access Control vulnerability — Slide Banners 4.3 Medium2025-02-07
CVE-2025-25110 WordPress Event Kikfyre plugin <= 2.1.8 - Broken Access Control vulnerability — Event Kikfyre 5.4 Medium2025-02-07
CVE-2025-25081 WordPress Embed RSS plugin <= 3.1 - Arbitrary Shortcode Execution vulnerability — Embed RSS 4.8 Medium2025-02-07
CVE-2024-3976 Missing Authorization in GitLab — GitLab 6.5 Medium2025-02-05
CVE-2024-1539 Missing Authorization in GitLab — GitLab 4.3 Medium2025-02-05
CVE-2025-22730 WordPress Ksher plugin <= 1.1.2 - Broken Access Control vulnerability — Ksher 6.5 Medium2025-02-04
CVE-2025-22643 WordPress OnePress theme <= 2.3.11 - Broken Access Control vulnerability — OnePress 4.3 Medium2025-02-04
CVE-2025-22696 WordPress Document Block – Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin <= 1.1.0 - Broken Access Control vulnerability — Document Block – Upload & Embed Docs 5.4 Medium2025-02-04
CVE-2024-13529 SocialV - Social Network and Community BuddyPress Theme <= 2.0.15 - Missing Authorization to Arbitrary File Download — SocialV - Social Network and Community BuddyPress Theme 6.5 Medium2025-02-04
CVE-2024-11134 Eventer <= 3.9.9 - Missing Authorization to Authenticated (Subscriber+) Bookings Export — Eventer - WordPress Event & Booking Manager Plugin 4.3 Medium2025-02-03
CVE-2024-11133 Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download — Eventer - WordPress Event & Booking Manager Plugin 5.3 Medium2025-02-03
CVE-2025-22694 WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerability — Hide Shipping Method For WooCommerce 4.3 Medium2025-02-03
CVE-2025-22686 WordPress CF7 Google Sheets Connector plugin <= 5.0.17 - Broken Access Control vulnerability — CF7 Google Sheets Connector 5.3 Medium2025-02-03
CVE-2025-22681 WordPress Content Cloner plugin <= 1.0.1 - Broken Access Control vulnerability — Content Cloner 4.3 Medium2025-02-03
CVE-2025-22677 WordPress Uix Shortcodes plugin <= 2.0.3 - Arbitrary Shortcode Execution vulnerability — Uix Shortcodes 4.8 Medium2025-02-03
CVE-2025-22260 WordPress Meta Tag Manager plugin <= 3.1 - Broken Access Control vulnerability — Meta Tag Manager 4.3 Medium2025-02-03
CVE-2024-50500 WordPress Phlox Core Elements plugin <= 2.17.4 - Broken Access Control vulnerability — Shortcodes and extra features for Phlox theme 4.3 Medium2025-02-03

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.