Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5529

5529 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-69354 WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability — Better Business Reviews 4.3 Medium2026-01-06
CVE-2025-69353 WordPress Proxy & VPN Blocker plugin <= 3.5.3 - Broken Access Control vulnerability — Proxy & VPN Blocker 4.3 Medium2026-01-06
CVE-2025-69352 WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability — The Events Calendar 5.4 Medium2026-01-06
CVE-2025-69349 WordPress RSS Feed Widget plugin <= 3.0.2 - Broken Access Control vulnerability — RSS Feed Widget 5.4 Medium2026-01-06
CVE-2025-69348 WordPress The Events Calendar Countdown Addon plugin <= 1.4.15 - Broken Access Control vulnerability — The Events Calendar Countdown Addon 4.3 Medium2026-01-06
CVE-2025-69345 WordPress Post and Page Builder by BoldGrid plugin <= 1.27.9 - Broken Access Control vulnerability — Post and Page Builder by BoldGrid 4.3 Medium2026-01-06
CVE-2025-69336 WordPress Ultimate Store Kit Elementor Addons plugin <= 2.9.4 - Broken Access Control vulnerability — Ultimate Store Kit Elementor Addons 4.3 Medium2026-01-06
CVE-2025-69346 WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability — AffiliateX 4.3 Medium2026-01-06
CVE-2025-69341 WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.3 - Broken Access Control vulnerability — WeDesignTech Ultimate Booking Addon 5.4 Medium2026-01-06
CVE-2025-69331 WordPress Theater for WordPress plugin <= 0.19 - Broken Access Control vulnerability — Theater for WordPress 4.3 Medium2026-01-06
CVE-2025-69327 WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability — Car Rental Manager 4.3 Medium2026-01-06
CVE-2025-9637 Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads — Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker 6.5 Medium2026-01-06
CVE-2025-5919 Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification — Timetics – Appointment Booking & Scheduling 6.5 Medium2026-01-06
CVE-2025-13964 LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 5.3 Medium2026-01-06
CVE-2025-13766 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion — MasterStudy LMS WordPress Plugin – for Online Courses and Education 5.4 Medium2026-01-06
CVE-2025-13812 GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress 4.3 Medium2026-01-06
CVE-2025-14371 TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification — Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI 4.3 Medium2026-01-06
CVE-2025-14441 Popupkit <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers 4.3 Medium2026-01-06
CVE-2025-14034 ilGhera Support System for WooCommerce <= 1.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Deletion — ilGhera Support System for WooCommerce 5.3 Medium2026-01-06
CVE-2025-11370 Depicter <= 4.0.7 - Missing Authorization to Unauthenticated Display Rule Updates — Depicter — Popup & Slider Builder 5.3 Medium2026-01-06
CVE-2025-39561 WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Broken Access Control vulnerability — LoginWP - Pro 6.5 Medium2026-01-05
CVE-2025-46255 WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Settings Change vulnerability — LoginWP - Pro 7.5 High2026-01-05
CVE-2025-68850 WordPress Sell Downloads plugin <= 1.1.12 - Broken Access Control vulnerability — Sell Downloads 6.5 -2026-01-05
CVE-2025-68547 WordPress Follow My Blog Post plugin <= 2.4.0 - Arbitrary Content Deletion vulnerability — Follow My Blog Post 7.5 High2026-01-05
CVE-2025-31046 WordPress AnyWhere Elementor Pro plugin <= 2.29 - Broken Access Control Vulnerability — AnyWhere Elementor Pro 4.3 Medium2026-01-05
CVE-2025-12519 Information disclosure on Administration parameters API endpoint — Infra Monitoring 5.3 Medium2026-01-05
CVE-2025-15235 Quanta Computer|QOCA aim AI Medical Cloud Platform - Missing Authorization — QOCA aim AI Medical Cloud Platform 6.5 Medium2026-01-05
CVE-2025-15115 Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint — Smart Pet Feeder Platform 6.5 Medium2026-01-03
CVE-2025-34171 CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure — CasaOS--2026-01-03
CVE-2026-21429 Emlog has Broken Access Control (BAC) — emlog 3.8 -2026-01-02

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.