Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-68608 WordPress Userpro plugin <= 5.1.9 - Broken Access Control vulnerability — Userpro 7.5 High2025-12-24
CVE-2025-68535 WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerability — Sunshine Photo Cart 4.3 Medium2025-12-24
CVE-2025-68522 WordPress WpStream plugin <= 4.9.5 - Broken Access Control vulnerability — WpStream 4.3 Medium2025-12-24
CVE-2025-68523 WordPress Spiffy Calendar plugin <= 5.0.7 - Broken Access Control vulnerability — Spiffy Calendar 4.3 Medium2025-12-24
CVE-2025-68521 WordPress WpStream plugin <= 4.9.5 - Broken Access Control vulnerability — WpStream 5.3 Medium2025-12-24
CVE-2025-68517 WordPress Tablesome plugin <= 1.1.35.1 - Broken Access Control vulnerability — Tablesome 5.4 Medium2025-12-24
CVE-2025-68511 WordPress Gutenverse Form plugin <= 2.3.1 - Broken Access Control vulnerability — Gutenverse Form 6.5 Medium2025-12-24
CVE-2025-68508 WordPress Brave plugin <= 0.8.3 - Broken Access Control vulnerability — Brave 5.3 Medium2025-12-24
CVE-2025-68505 WordPress H5P plugin <= 1.16.1 - Broken Access Control vulnerability — H5P 5.3 Medium2025-12-24
CVE-2024-24844 WordPress PowerPack Pro for Elementor plugin <= 2.10.6 - Unauthenticated Plugin Settings Reset vulnerability — PowerPack Pro for Elementor 7.5 High2025-12-23
CVE-2025-68556 WordPress HAPPY plugin <= 1.0.9 - Broken Access Control vulnerability — HAPPY 5.3 Medium2025-12-23
CVE-2025-68557 WordPress Chakra test plugin <= 1.0.1 - Broken Access Control vulnerability — Chakra test 4.3 Medium2025-12-23
CVE-2025-12934 Beaver Builder – WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update — Beaver Builder Page Builder – Drag and Drop Website Builder 8.1 High2025-12-23
CVE-2025-14155 Premium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content' — Premium Addons for Elementor – Powerful Elementor Templates & Widgets 5.3 Medium2025-12-23
CVE-2025-12980 Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX 7.5 High2025-12-21
CVE-2025-14043 Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation — Tainacan 5.3 Medium2025-12-21
CVE-2025-14080 Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary Post Modification — Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin 5.3 Medium2025-12-21
CVE-2023-25446 WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability — HappyFiles Pro 7.7 High2025-12-21
CVE-2023-25445 WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability — HappyFiles Pro 5.4 Medium2025-12-21
CVE-2023-25068 WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activation — Magazine Edge 4.3 Medium2025-12-20
CVE-2025-7782 WP JobHunt <= 7.7 - Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scripting via 'status' — WP JobHunt 7.6 High2025-12-20
CVE-2025-14633 F70 Lead Document Download <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Media File Download — F70 Lead Document Download 5.3 Medium2025-12-20
CVE-2025-12898 Pretty Google Calendar <= 2.0.0 - Missing Authorization to Unauthenticated Google API Key Exposure — Pretty Google Calendar 5.3 Medium2025-12-20
CVE-2025-14455 Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management — Image Photo Gallery Final Tiles Grid 5.4 Medium2025-12-19
CVE-2025-12361 myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 - Missing Authorization to Sensitive Information Exposure — Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred 4.3 Medium2025-12-19
CVE-2025-13754 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 5.3 Medium2025-12-19
CVE-2020-36890 Kentico Xperience <= 10 Administrator Access Control Bypass — Xperience 7.2 High2025-12-18
CVE-2025-62960 WordPress Construction Light theme <= 1.6.7 - Broken Access Control vulnerability — Construction Light 5.4 Medium2025-12-18
CVE-2025-62961 WordPress Sparkle FSE theme <= 1.0.9 - Broken Access Control vulnerability — Sparkle FSE 5.4 Medium2025-12-18
CVE-2025-63002 WordPress Sermon Manager plugin <= 2.30.0 - Broken Access Control vulnerability — Sermon Manager 5.3 Medium2025-12-18

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.