Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11812 Wtyczka SeoPilot dla WP <= 3.3.091 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Wtyczka SeoPilot dla WPCWE-352 6.1 Medium2024-12-20
CVE-2024-12571 Store Locator <= 3.98.10 - Unauthenticated Local File Inclusion — Store Locator for WordPress with Google Maps – LotsOfLocalesCWE-98 9.8 Critical2024-12-20
CVE-2020-9250 Micro Focus Vibe 跨站脚本漏洞 — HUAWEI Mate 20 ProCWE-287 3.3 Low2024-12-20
CVE-2024-12727 Sophos Firewall 安全漏洞 — Sophos FirewallCWE-89 9.8 Critical2024-12-19
CVE-2024-56159 Server source code is exposed to the public if sourcemaps are enabled — astroCWE-219 7.5 -2024-12-19
CVE-2024-12626 AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value — AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressCWE-79 9.6 Critical2024-12-19
CVE-2024-11768 Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files — Download ManagerCWE-285 5.3 Medium2024-12-19
CVE-2024-11740 Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution — Download ManagerCWE-94 7.3 High2024-12-19
CVE-2023-21586 Acrobat Reader | NULL Pointer Dereference (CWE-476) — Acrobat ReaderCWE-476 5.5 Medium2024-12-18
CVE-2024-11291 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content RestrictionCWE-200 5.3 Medium2024-12-18
CVE-2024-11912 Traveler <= 3.1.6 - Unauthenticated SQL Injection via order_id — Travel Booking WordPress ThemeCWE-89 7.5 High2024-12-18
CVE-2024-12454 Affiliate Program Suite — SliceWP Affiliates <= 1.1.23 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — Affiliate Program Suite — SliceWP AffiliatesCWE-352 6.1 Medium2024-12-18
CVE-2024-12554 Peter’s Custom Anti-Spam <= 3.2.3 - Cross-Site Request Forgery via cas_register_post Function — Peter’s Custom Anti-SpamCWE-352 5.4 Medium2024-12-18
CVE-2024-11295 Simple Page Access Restriction <= 1.0.29 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Simple Page Access RestrictionCWE-200 5.3 Medium2024-12-18
CVE-2024-12287 Biagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_user — Biagiotti MembershipCWE-287 9.8 Critical2024-12-18
CVE-2024-12698 Ose-olm-catalogd-container: incomplete fix for rapid reset (cve-2023-39325/cve-2023-44487) CWE-400 6.5 Medium2024-12-18
CVE-2024-12250 Accept Authorize.NET Payments Using Contact Form 7 <= 2.2 - Unauthenticated Information Exposure — Accept Authorize.NET Payments Using Contact Form 7CWE-200 5.3 Medium2024-12-18
CVE-2024-11254 AMP for WP – Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting — AMP for WP – Accelerated Mobile PagesCWE-79 6.1 Medium2024-12-18
CVE-2024-12025 Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection — Collapsing CategoriesCWE-89 7.5 High2024-12-18
CVE-2024-11280 PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — PPWP – Password Protect PagesCWE-200 5.3 Medium2024-12-17
CVE-2024-12395 WooCommerce Additional Fees On Checkout (Free) <= 1.4.7 - Reflected Cross-Site Scripting via 'number' — Additional Fees For WooCommerce CheckoutCWE-79 6.1 Medium2024-12-17
CVE-2024-9654 Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass — Easy Digital Downloads – eCommerce Payments and Subscriptions made easyCWE-863 3.7 Low2024-12-17
CVE-2024-12601 Calculated Fields Form <= 5.2.63 - Denial of Service — Calculated Fields FormCWE-400 5.3 Medium2024-12-17
CVE-2024-12024 EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name — EventPrime – Events Calendar, Bookings and TicketsCWE-79 7.2 High2024-12-17
CVE-2024-12127 Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter — Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMSCWE-80 6.1 Medium2024-12-17
CVE-2024-12469 WP BASE Booking of Appointments, Services and Events <= 4.9.1 - Reflected Cross-Site Scripting via status Parameter — WP BASE Booking of Appointments, Services and EventsCWE-79 6.1 Medium2024-12-17
CVE-2024-12293 User Role Editor <= 4.64.3 - Cross-Site Request Forgery to Privilege Escalation — User Role EditorCWE-352 8.8 High2024-12-17
CVE-2024-11294 Memberful <= 1.73.9 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Memberful – Membership PluginCWE-200 5.3 Medium2024-12-17
CVE-2024-12220 SMS for WooCommerce <= 2.8.1 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — SMS for WooCommerceCWE-352 6.1 Medium2024-12-17
CVE-2024-12219 Stop Registration Spam <= 1.23 - Cross-Site Request Forgery to Cross-Site Scripting — Stop Registration SpamCWE-352 6.1 Medium2024-12-17

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.