Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0629 2Checkout Payment Gateway for WooCommerce <= 6.2 - Missing Authorization via sniff_ins — 2Checkout Payment Gateway for WooCommerceCWE-862 5.3 Medium2024-05-02
CVE-2024-3715 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting — Database for Contact Form 7, WPforms, Elementor formsCWE-79 7.2 High2024-05-02
CVE-2024-3215 Paid Memberships Pro <= 3.0.1 - Cross-Site Request Forgery — Paid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-352 5.3 Medium2024-05-02
CVE-2024-3729 Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation — Frontend Admin by DynamiAppsCWE-636 9.8 Critical2024-05-02
CVE-2024-0615 Content Control <= 2.1.0 - Missing Authorization to Sensitive Information Exposure — Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & MoreCWE-200 5.3 Medium2024-05-02
CVE-2024-2797 MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization — MailerLite – Signup forms (official)CWE-862 5.3 Medium2024-05-02
CVE-2024-3287 SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.2 - Missing Authorization — SmartCrawl SEO checker, analyzer & optimizerCWE-862 5.3 Medium2024-05-02
CVE-2024-3870 Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information Exposure — Database Addon for Contact Form 7 – CFDB7CWE-200 5.3 Medium2024-05-02
CVE-2024-0848 AA Cash Calculator <= 1.0 - Reflected Cross-Site Scripting via invoice — AA Cash CalculatorCWE-79 6.1 Medium2024-05-02
CVE-2024-0908 Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure — Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and FiltersCWE-862 5.3 Medium2024-05-02
CVE-2024-3312 Easy Custom Auto Excerpt <= 2.4.12 - Sensitive Information Exposure — Easy Custom Auto ExcerptCWE-862 5.3 Medium2024-05-02
CVE-2024-2109 Booster Extension <= 1.2.0 - Basic Information Exposure via booster_extension_authorbox_shortcode_display — Booster ExtensionCWE-862 5.3 Medium2024-05-02
CVE-2024-3295 User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-862 6.5 Medium2024-05-02
CVE-2024-4133 ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.30 - Open Redirect — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-601 6.1 Medium2024-05-02
CVE-2024-2959 SVS Pricing Tables <= 1.0.4 - Cross-Site Request Forgery to Pricing Table Edit/Creation — SVS Pricing TablesCWE-352 4.3 Medium2024-05-02
CVE-2024-3489 Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title — Exclusive Addons for ElementorCWE-79 6.4 Medium2024-05-02
CVE-2024-1567 Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-434 8.2 High2024-05-02
CVE-2024-2043 EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.7 - Missing Authorization to Sensitive Information Exposure — EleForms – All In One Form Integration including DB for ElementorCWE-862 5.3 Medium2024-05-02
CVE-2024-3649 Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation — WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & MoreCWE-472 5.3 Medium2024-05-02
CVE-2024-1688 Woo Total Sales <= 3.1.4 - Missing Authorization to Unauthenticated Sales Report Retrieval — Woo Total SalesCWE-862 5.3 Medium2024-05-02
CVE-2024-1678 Subway – Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST API — Subway – Private Site OptionCWE-284 5.3 Medium2024-05-02
CVE-2023-6214 HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products — HT Mega Addons for Elementor – Elementor Widgets & Template BuilderCWE-200 7.5 High2024-05-02
CVE-2024-3734 FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution — FOX – Currency Switcher Professional for WooCommerceCWE-94 6.5 Medium2024-05-02
CVE-2024-3599 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Cookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-862 5.3 Medium2024-05-02
CVE-2024-3045 PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting — PDF Invoices & Packing Slips for WooCommerceCWE-79 7.2 High2024-05-02
CVE-2024-1584 Analytify <= 5.2.1 - Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking)CWE-284 5.3 Medium2024-05-02
CVE-2024-3047 PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery — PDF Invoices & Packing Slips for WooCommerceCWE-918 7.2 High2024-05-02
CVE-2024-0847 5280 Bootstrap Modal Contact Form <= 1.0 - Cross-Site Request Forgery to Bulk Delete Messages — 5280 Bootstrap Modal Contact FormCWE-352 4.3 Medium2024-05-02
CVE-2024-3957 Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution — Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ ToolsCWE-94 6.5 Medium2024-05-02
CVE-2024-3717 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure — Drag and Drop Multiple File Upload for Contact Form 7CWE-922 5.3 Medium2024-05-02

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.