Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-8488 Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update — Ultimate Addons for Elementor 4.3 Medium2025-08-02
CVE-2025-8152 WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unauthenticated Sticky Status Update — WP CTA – Call Now Button, Sticky Button & Call to Action Builder 5.3 Medium2025-08-02
CVE-2025-6754 SEO Metrics <= 1.0.15 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation — SEO Metrics 8.8 High2025-08-02
CVE-2025-8435 code-projects Online Movie Streaming admin-control.php authorization — Online Movie Streaming 7.3 High2025-08-01
CVE-2025-8434 code-projects Online Movie Streaming admin.php authorization — Online Movie Streaming 7.3 High2025-08-01
CVE-2025-46811 SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint — Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 9.8 Critical2025-07-30
CVE-2025-8322 Ventem|e-School - Missing Authorization — e-School 8.8 High2025-07-30
CVE-2025-7689 Hydra Booking 1.1.0 - 1.1.18 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function — Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings 8.8 High2025-07-29
CVE-2025-6730 Bonanza – WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success — Bonanza – WooCommerce Free Gifts Lite 4.3 Medium2025-07-29
CVE-2025-4370 Brizy <= 2.6.20 - Missing Authorization to Unauthenticated Limited File Upload — Brizy – Page Builder 5.3 Medium2025-07-29
CVE-2023-7306 Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Frontend File Manager Plugin 7.5 High2025-07-25
CVE-2025-5835 Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions — Droip 8.8 High2025-07-25
CVE-2015-10143 Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update — Platform 9.8 Critical2025-07-25
CVE-2025-7695 Dataverse Integration 2.77 - 2.81 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via reset_password_link REST Route — Dataverse Integration 8.8 High2025-07-24
CVE-2025-6380 ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback Function — ONLYOFFICE Docs 9.8 Critical2025-07-24
CVE-2025-7822 WP Wallcreeper <= 1.6.1 - Missing Authorization to Authenticated (Susbcriber+) Cache Enable/Disable — WP Wallcreeper 4.3 Medium2025-07-24
CVE-2025-6441 Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition <= 4.03.32 - Unauthenticated Login Token Generation to Authentication Bypass — WebinarIgnition – Live, Automated & Evergreen Webinars for WooCommerce 9.8 Critical2025-07-24
CVE-2025-1299 Missing Authorization in GitLab — GitLab 4.3 Medium2025-07-24
CVE-2025-6190 Realty Portal – Agent <= 0.3.9 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via rp_user_profile() Function — Realty Portal – Agent 8.8 High2025-07-23
CVE-2025-6215 Omnishop <= 1.0.9 - Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint — Omnishop – Mobile shop apps complementing your WooCommerce webshop 5.3 Medium2025-07-23
CVE-2025-6187 bSecure 1.3.7 - 1.7.9 - Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint — bSecure – Your Universal Checkout 9.8 Critical2025-07-22
CVE-2025-7717 File Download - Moderately critical - Access bypass - SA-CONTRIB-2025-089 — File Download 9.1 -2025-07-21
CVE-2025-6720 Vchasno Kasa <= 1.0.3 - Unauthenticated Log File Clearing — MORKVA Vchasno Kasa Integration 5.3 Medium2025-07-19
CVE-2025-6721 Vchasno Kasa <= 1.0.3 - Missing Authorization to Unauthenticated Invoice Generation — MORKVA Vchasno Kasa Integration 5.3 Medium2025-07-19
CVE-2025-49747 Azure Machine Learning Elevation of Privilege Vulnerability — Azure Machine Learning 9.9 Critical2025-07-18
CVE-2025-7772 Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal <= 16.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read — Malcure Malware Shield — Removal, Repair, Monitor 6.5 Medium2025-07-18
CVE-2025-5811 Listly: Listicles For WordPress <= 2.7 - Unauthenticated Arbitrary Transient Deletion — Listly: Listicles For WordPress 5.3 Medium2025-07-18
CVE-2025-6726 Block Editor Gallery Slider <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update — Block Editor Gallery Slider for WordPress – Image Slider, Gallery Carousel & Lightbox Plugin 4.3 Medium2025-07-18
CVE-2025-6718 B1.lt for WooCommerce <= 2.2.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection — Site.pro for WooCommerce 8.8 High2025-07-18
CVE-2025-6813 aapanel WP Toolkit 1.0 - 1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via auto_login() Function — aapanel WP Toolkit 8.8 High2025-07-18

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.