Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18860

18860 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13719 PeproDev Ultimate Invoice <= 2.0.9 - Insecure Direct Object Reference to Unauthenticated Order Information Exposure — PeproDev Ultimate InvoiceCWE-862 5.3 Medium2025-02-19
CVE-2024-13712 Pollin <= 1.01.1 - Authenticated (Admin+) SQL Injection — PollinCWE-89 4.9 Medium2025-02-19
CVE-2025-0865 WP Media Category Management 2.0 - 2.3.3 - Cross-Site Request Forgery to Settings Update — WP Media Category ManagementCWE-352 6.5 Medium2025-02-19
CVE-2025-1441 Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 6.1 Medium2025-02-19
CVE-2024-11582 Subscribe2 – Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scripting via IP Parameter — Subscribe2 – Form, Email Subscribers & NewslettersCWE-79 7.2 High2025-02-19
CVE-2024-13508 Booking Package <= 1.6.72 - Reflected Cross-Site Scripting via Locale Parameter — Booking PackageCWE-79 6.1 Medium2025-02-18
CVE-2025-25284 Path Traversal and Local File Read via VRT (Virtual Format) in ZOO-Project WPS Implementation — ZOO-ProjectCWE-22 6.2 -2025-02-18
CVE-2025-0817 FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload — FormCraftCWE-79 7.2 High2025-02-18
CVE-2025-0521 Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile AppCWE-79 7.2 High2025-02-18
CVE-2024-13681 Uncode <= 2.9.1.6 - Unauthenticated Arbitrary File Read in uncode_admin_get_oembed — UncodeCWE-20 7.5 High2025-02-18
CVE-2024-13797 PressMart - Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution — PressMart - Modern Elementor WooCommerce WordPress ThemeCWE-94 7.3 High2025-02-18
CVE-2024-12860 CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover — CarSpot – Dealership Wordpress Classified ThemeCWE-620 9.8 Critical2025-02-18
CVE-2024-13316 Scratch & Win – Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation — Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and moreCWE-862 5.3 Medium2025-02-18
CVE-2024-13718 Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification — Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for laterCWE-352 4.3 Medium2025-02-18
CVE-2025-0423 Multiple Unauthenticated Stored Cross-Site Scripting — bestinformed WebCWE-20 6.1 -2025-02-18
CVE-2025-0864 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cross-Site Scripting — Active Products Tables for WooCommerce. Use constructor to create tablesCWE-79 6.1 Medium2025-02-18
CVE-2024-13795 Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message — Ecwid by Lightspeed Ecommerce Shopping CartCWE-352 4.3 Medium2025-02-18
CVE-2024-13704 Super Testimonials <= 4.0.1 - Unauthenticated Stored Cross-Site Scripting — Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPressCWE-80 7.2 High2025-02-18
CVE-2024-11376 s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241216 - Reflected Cross-Site Scripting — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access SubscriptionsCWE-79 6.1 Medium2025-02-18
CVE-2024-13523 MemorialDay <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting — MemorialDayCWE-352 6.1 Medium2025-02-18
CVE-2024-13315 Shopwarden – Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update — Shopwarden – Automated WooCommerce monitoring & testingCWE-352 8.8 High2025-02-18
CVE-2024-13438 SpeedSize Image & Video AI-Optimizer <= 1.5.1 - Cross-Site Request Forgery to Clear Cache — SpeedSize Image & Video AI-OptimizerCWE-352 4.3 Medium2025-02-18
CVE-2024-13556 Affiliate Links: WordPress Plugin for Link Cloaking and Link Management <= 3.0.1 - Missing Authorization to Unauthenticated Import/Export and PHP Object Injection — Affiliate Links – Link Cloaking and ManagementCWE-862 8.1 High2025-02-18
CVE-2024-13609 1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Unauthenticated Sensitive Information Exposure via Database Backup in class-ocm-backup.php — 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy CloneCWE-200 5.9 Medium2025-02-18
CVE-2024-13555 1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Cross-Site Request Forgery to Backup Process Cancellation — 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy CloneCWE-352 5.3 Medium2025-02-18
CVE-2024-13622 File Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — File Uploads Addon for WooCommerceCWE-200 7.5 High2025-02-18
CVE-2024-12314 Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning — Rapid CacheCWE-524 7.2 High2025-02-18
CVE-2024-13535 Actionwear products sync <= 2.3.2 - Unauthenticated Full Patch Disclosure — Actionwear products syncCWE-209 5.3 Medium2025-02-18
CVE-2024-13725 Keap Official Opt-in Forms <= 2.0.1 - Unauthenticated Limited Local File Inclusion — Keap Official Opt-in FormsCWE-22 9.8 Critical2025-02-18
CVE-2024-13540 WooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure — WooODT Lite – Delivery & pickup date time location for WooCommerceCWE-209 5.3 Medium2025-02-18

Vulnerabilities classified as access:pre-auth represent 18860 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.