Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18857

18857 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13904 Platform.ly for WooCommerce <= 1.1.6 - Unauthenticated Blind Server-Side Request Forgery — Platform.ly for WooCommerceCWE-918 5.3 Medium2025-03-07
CVE-2024-10804 Ultimate Video Player <= 10.0 - Unauthenticated Arbitrary File Download — Ultimate Video Player WordPress & WooCommerce PluginCWE-22 7.5 High2025-03-07
CVE-2024-12611 School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting — School Management System for WordpressCWE-862 5.3 Medium2025-03-07
CVE-2024-13320 CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection — CURCY - WooCommerce Multi Currency - Currency SwitcherCWE-89 7.5 High2025-03-07
CVE-2025-1475 WPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone' — WPCOM MemberCWE-287 9.8 Critical2025-03-07
CVE-2025-0748 Homey <= 2.4.3 - Cross-Site Request Forgery to User Verification — HomeyCWE-352 4.3 Medium2025-03-07
CVE-2025-0749 Homey <= 2.4.3 - Limited Authentication Bypass due to Missing Empty Value Check — HomeyCWE-288 8.1 High2025-03-07
CVE-2025-1383 Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function — Podlove Podcast PublisherCWE-352 4.3 Medium2025-03-06
CVE-2025-26167 Buffalo LS520D 信息泄露漏洞 — n/a 7.5 -2025-03-06
CVE-2024-11153 Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & MoreCWE-200 5.3 Medium2025-03-05
CVE-2024-11951 Homey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_register — Homey Login RegisterCWE-269 9.8 Critical2025-03-05
CVE-2024-12281 Homey <= 2.4.2 - Unauthenticated Privilege Escalation in homey_save_profile — HomeyCWE-269 9.8 Critical2025-03-05
CVE-2024-13423 Sparkling <= 2.4.9 - Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation — SparklingCWE-862 5.3 Medium2025-03-05
CVE-2024-13471 DesignThemes Core Features <= 4.7 - Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file — DesignThemes Core FeaturesCWE-22 7.5 High2025-03-05
CVE-2025-1702 Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-89 7.5 High2025-03-05
CVE-2025-1463 Spreadsheet Integration <= 3.8.2 - Cross-Site Request Forgery to Arbitrary Post Publish — WPGSI: Spreadsheet IntegrationCWE-352 4.3 Medium2025-03-05
CVE-2024-13815 Listingo - Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution — ListingoCWE-94 6.5 Medium2025-03-05
CVE-2024-13839 Company Directory <= 4.3 - Reflected Cross-Site Scripting via add_query_arg Function — Staff Directory Plugin: Company DirectoryCWE-79 6.1 Medium2025-03-05
CVE-2025-1515 WP Real Estate Manager <= 2.8 - Authentication Bypass via Account Takeover — WP Real Estate ManagerCWE-288 9.8 Critical2025-03-05
CVE-2025-0954 WP Online Contract <= 5.1.4 - Missing Authorization to Unauthenticated Settings Import — WP Online ContractCWE-862 6.5 Medium2025-03-05
CVE-2024-13777 ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection — ZoomSounds - WordPress Wave Audio Player with PlaylistCWE-502 8.1 High2025-03-05
CVE-2024-13779 Hero Mega Menu - Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting — Hero Mega Menu - Responsive WordPress Menu PluginCWE-79 6.1 Medium2025-03-05
CVE-2024-13780 Hero Mega Menu - Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion — Hero Mega Menu - Responsive WordPress Menu PluginCWE-862 6.5 Medium2025-03-05
CVE-2025-0956 WooCommerce Recover Abandoned Cart <= 24.4.0 - Unauthenticated PHP Object Injection — WooCommerce Recover Abandoned CartCWE-502 8.1 High2025-03-05
CVE-2024-13827 Razorpay Subscription Button Elementor Plugin <= 1.0.3 - Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions — Razorpay Subscription Button Elementor PluginCWE-79 6.1 Medium2025-03-05
CVE-2024-8682 JNews - WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration — JNews - WordPress Newspaper Magazine Blog AMP ThemeCWE-862 5.3 Medium2025-03-05
CVE-2025-0990 I Am Gloria <= 1.1.4 - Cross-Site Request Forgery — I Am GloriaCWE-352 4.3 Medium2025-03-05
CVE-2025-1435 bbPress <= 2.6.11 - Cross-Site Request Forgery to Limited Privilege Escalation — bbPressCWE-352 6.3 Medium2025-03-05
CVE-2025-1393 Weidmueller: Authentication Vulnerability due to Hard-coded Credentials — PROCON-WINCWE-798 9.8 Critical2025-03-05
CVE-2025-27641 Vasion Print 授权问题漏洞 — n/a 9.8 -2025-03-05

Vulnerabilities classified as access:pre-auth represent 18857 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.