Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-2325 Link Library <= 7.6.6 - Reflected Cross-Site Scripting — Link LibraryCWE-79 6.1 Medium2024-04-09
CVE-2024-3136 MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-98 9.8 Critical2024-04-09
CVE-2024-3214 Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection — Relevanssi PremiumCWE-1236 5.8 Medium2024-04-09
CVE-2024-2340 Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing — Avada | Website Builder For WordPress & WooCommerceCWE-548 5.3 Medium2024-04-09
CVE-2024-1813 Simple Job Board <= 2.11.0 - Unauthenticated PHP Object Injection via Job Application Fields — Simple Job BoardCWE-502 9.8 Critical2024-04-09
CVE-2024-1934 WP Compress – Image Optimizer <= 6.11.08 - Missing Authorization to Unauthenticated CDN Modification — WP Compress – Instant Performance & Speed OptimizationCWE-862 7.5 High2024-04-09
CVE-2024-0899 s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access SubscriptionsCWE-284 5.3 Medium2024-04-09
CVE-2023-7046 WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score <= 7.0 - Sensitive Information Exposure via insufficiently protected files — WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL ScanCWE-200 7.5 High2024-04-09
CVE-2024-2974 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure — Essential Addons for Elementor – Popular Elementor Templates & WidgetsCWE-200 5.3 Medium2024-04-09
CVE-2024-3097 WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure — Photo Gallery, Sliders, Proofing and Themes – NextGEN GalleryCWE-862 5.3 Medium2024-04-09
CVE-2024-2543 Plugin Permalink <= 2.4.3.1 - Missing Authorization via get_uri_editor — Permalink Manager LiteCWE-639 4.3 Medium2024-04-09
CVE-2024-2738 Permalink Manager Lite and Permalink Manager Pro <= 2.4.3.1 - Reflected Cross-Site Scripting — Permalink Manager LiteCWE-79 6.1 Medium2024-04-09
CVE-2024-0588 Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery — Paid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-352 4.3 Medium2024-04-09
CVE-2023-6799 WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness — WP ResetCWE-330 5.9 Medium2024-04-09
CVE-2024-2198 Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_address — Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPressCWE-79 6.1 Medium2024-04-09
CVE-2024-0626 WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handler — Clover Payment Gateway by Zaytech for WooCommerceCWE-284 5.3 Medium2024-04-09
CVE-2024-2112 Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-287 5.9 Medium2024-04-09
CVE-2023-6777 WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service — WP Go Maps (formerly WP Google Maps)CWE-200 5.3 Medium2024-04-09
CVE-2024-1315 Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account — Classified Listing – AI-Powered Classified ads & Business Directory PluginCWE-352 8.8 High2024-04-09
CVE-2024-1308 WooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink Modification — Cloak Affiliate Links for WooCommerceCWE-284 7.5 High2024-04-09
CVE-2024-2804 Network Summary <= 2.0.11 - Unauthenticated SQL Injection — Network SummaryCWE-89 9.8 Critical2024-04-09
CVE-2024-2125 EnvíaloSimple: Email Marketing y Newsletters <= 2.3 - Cross-Site Request Forgery to Arbitrary File Upload — EnvíaloSimple: Email Marketing y NewslettersCWE-434 8.8 High2024-04-09
CVE-2024-1794 Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79 7.2 High2024-04-09
CVE-2024-2200 Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_subject — Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPressCWE-79 6.1 Medium2024-04-09
CVE-2024-1774 Customily Product Personalizer <= 1.23.3 - Unauthenticated Stored Cross-Site Scripting — Customily Product PersonalizerCWE-79 7.2 High2024-04-09
CVE-2024-2302 Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure — Easy Digital Downloads – eCommerce Payments and Subscriptions made easyCWE-532 5.3 Medium2024-04-09
CVE-2024-1852 WP-Members Membership Plugin <= 3.4.9.2 - Unauthenticated Stored Cross-Site Scripting — WP-Members Membership PluginCWE-79 7.2 High2024-04-09
CVE-2023-49074 TP-LINK AC1350 安全漏洞 — AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)CWE-749 7.4 High2024-04-09
CVE-2023-49133 TP-LINK AC1350 安全漏洞 — AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)CWE-829 8.1 High2024-04-09
CVE-2023-49134 TP-LINK AC1350 安全漏洞 — AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)CWE-829 8.1 High2024-04-09

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.