Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18942

18942 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0631 Duitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_response — Duitku Payment GatewayCWE-284 5.3 Medium2024-03-13
CVE-2024-0681 Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism Bypass — Page and Post RestrictionCWE-693 5.3 Medium2024-03-13
CVE-2023-7015 File Manager Pro <= 8.3.4 - Reflected Cross-Site Scripting — File Manager ProCWE-79 6.1 Medium2024-03-13
CVE-2024-0830 Comments Extra Fields For Post,Pages and CPT <= 5.0 - Cross-Site Request Forgery — Comments Extra Fields For Post,Pages and CPTCWE-352 4.3 Medium2024-03-13
CVE-2024-1985 Simple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site Scripting — Simple MembershipCWE-79 4.7 Medium2024-03-13
CVE-2023-6785 Download Manager <= 3.2.84 - Missing Authorization — Download ManagerCWE-284 5.3 Medium2024-03-13
CVE-2024-1380 Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export — Relevanssi PremiumCWE-862 5.3 Medium2024-03-13
CVE-2024-1691 Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload — Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-79 6.1 Medium2024-03-13
CVE-2024-1321 EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass — EventPrime – Events Calendar, Bookings and TicketsCWE-345 5.3 Medium2024-03-13
CVE-2024-1462 Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API — Maintenance PageCWE-284 5.3 Medium2024-03-13
CVE-2024-2172 Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation — Web Application Firewall – website securityCWE-304 9.8 Critical2024-03-13
CVE-2024-0592 Related Posts for WordPress <= 2.2.1 - Cross-Site Request Forgery — Related Posts for WordPressCWE-352 5.4 Medium2024-03-13
CVE-2024-0591 wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.2 - Reflected Cross-Site Scripting. — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts PluginCWE-79 6.1 Medium2024-03-13
CVE-2024-1763 Wp Social Login and Register Social Counter <= 3.0.0 - Missing Authorization to Unauthenticated Social Login/Share Status Update — Wp Social Login and Register Social CounterCWE-862 6.5 Medium2024-03-13
CVE-2024-0976 WP Event Manager <= 3.1.41 - Reflected Cross-Site Scripting via plugin — WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerceCWE-79 6.1 Medium2024-03-13
CVE-2024-1640 Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Reference to Form Submission Alteration — Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builderCWE-639 5.3 Medium2024-03-13
CVE-2024-2020 Calculated Fields Form Professional <= 5.1.56 - Unauthenticated Stored Cross-Site Scripting — Calculated Fields FormCWE-79 7.2 High2024-03-13
CVE-2024-1484 Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting — Booking for Appointments and Events Calendar – AmeliaCWE-79 6.1 Medium2024-03-13
CVE-2024-1383 WPvivid Backup for MainWP <= 0.9.32 - Reflected Cross-Site Scripting — WPvivid Backup for MainWPCWE-79 6.1 Medium2024-03-13
CVE-2024-1642 MainWP Dashboard <= 4.6.0.1 - Cross-Site Request Forgery via posting_bulk — MainWP Dashboard: Self-hosted WordPress Management for AgenciesCWE-352 4.3 Medium2024-03-13
CVE-2024-1935 Giveaways and Contests by RafflePress <= 1.12.5 - Unauthenticated Stored Cross-Site Scripting — Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social FollowersCWE-79 7.2 High2024-03-13
CVE-2024-2106 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-200 5.3 Medium2024-03-13
CVE-2024-0839 FeedWordPress <= 2022.0222 - Insecure Direct Object Referece — FeedWordPressCWE-639 5.3 Medium2024-03-13
CVE-2024-1176 HT Easy GA4 – Google Analytics WordPress Plugin <= 1.1.5 - Missing Authorization to Unauthenticated GA4 Email Update — HT Easy GA4 – Google Analytics WordPress PluginCWE-862 5.3 Medium2024-03-13
CVE-2024-1071 WordPress Plugin Ultimate Member 安全漏洞 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 9.8 Critical2024-03-13
CVE-2024-2123 Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79 7.2 High2024-03-13
CVE-2018-25090 Wago: Improper Neutralization of Input During Web Page Generation in multiple devices — Controller BACnet/IPCWE-79 5.4 Medium2024-03-13
CVE-2015-10130 WordPress Plugin Team Circle Image Slider With Lightbox 安全漏洞 — Team Circle Image Slider With Lightbox 5.3 Medium2024-03-13
CVE-2024-1214 Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery — Easy Social Feed – Social Photos Gallery and Post Feed for WordPressCWE-352 4.3 Medium2024-03-12
CVE-2024-1213 Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery — Easy Social Feed – Social Photos Gallery and Post Feed for WordPressCWE-352 5.4 Medium2024-03-12

Vulnerabilities classified as access:pre-auth represent 18942 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.