Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18946

18946 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0428 Index Now <= 2.6.3 - Cross-Site Request Forgery via reset_form — CrawlWP SEO – Instant Search Engine Indexing & SEO Performance MonitorCWE-352 7.1 High2024-02-05
CVE-2023-4637 WPvivid <= 0.9.94 - Missing Authorization — WPvivid — Backup, Migration & StagingCWE-862 4.3 Medium2024-02-05
CVE-2024-0660 Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-352 6.1 Medium2024-02-05
CVE-2024-0709 WordPress plugin Cryptocurrency Widgets 安全漏洞 — Cryptocurrency Widgets – Price Ticker & Coins List 9.8 Critical2024-02-05
CVE-2024-1208 LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2023-6933 Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection — Better Search ReplaceCWE-502 8.8 High2024-02-05
CVE-2024-1121 Advanced Forms for ACF <= 1.9.3.2 - Missing Authorization to Unauthenticated Form Settings Export — Advanced Forms for ACFCWE-862 5.3 Medium2024-02-05
CVE-2024-1072 Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage — Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance ModeCWE-862 8.2 High2024-02-05
CVE-2024-1075 Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass — Minimal Coming Soon – Coming Soon PageCWE-639 3.7 Low2024-02-05
CVE-2024-0678 Order Delivery Date for WP e-Commerce <= 1.2 - Unauthenticated Stored Cross-Site Scripting — Order Delivery Date for WP e-CommerceCWE-79 6.5 Medium2024-02-05
CVE-2024-1209 LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2024-0509 WP 404 Auto Redirect to Similar Post <= 1.0.3 - Reflected Cross-Site Scripting via request — WP 404 Auto Redirect to Similar PostCWE-79 6.1 Medium2024-02-05
CVE-2024-0790 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery — WOLF – WordPress Posts Bulk Editor and Manager ProfessionalCWE-352 5.4 Medium2024-02-05
CVE-2024-1177 WP Club Manager – WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update — WP Club Manager – WordPress Sports Club PluginCWE-862 5.3 Medium2024-02-05
CVE-2024-1210 LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2023-7014 Author Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debug — Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPressCWE-359 5.3 Medium2024-02-05
CVE-2024-0796 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Cross-Site Request Forgery — Active Products Tables for WooCommerce. Use constructor to create tablesCWE-352 4.3 Medium2024-02-05
CVE-2024-0859 Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery — Affiliates ManagerCWE-352 4.3 Medium2024-02-05
CVE-2024-0374 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_view — Views for WPForms – Display & Edit WPForms Entries on your site frontendCWE-284 4.3 Medium2024-02-05
CVE-2024-0324 User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-284 8.2 High2024-02-05
CVE-2024-0761 File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames — File ManagerCWE-330 8.1 High2024-02-05
CVE-2023-6989 Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion — Shield: Blocks Bots, Protects Users, and Prevents Security BreachesCWE-98 9.8 Critical2024-02-05
CVE-2024-22208 phpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes — phpMyFAQCWE-863 6.5 Medium2024-02-05
CVE-2023-7216 Cpio: extraction allows symlinks which enables remote command execution — Red Hat Enterprise Linux 6CWE-59 5.3 Medium2024-02-05
CVE-2021-4436 3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload — 3DPrint Lite 9.1 -2024-02-05
CVE-2024-1064 Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4 — Crafty ControllerCWE-644 7.5 High2024-02-03
CVE-2024-0909 Anonymous Restricted Content <= 1.6.2 - Protection Mechanism Bypass — Anonymous Restricted ContentCWE-200 5.3 Medium2024-02-03
CVE-2022-34381 Dell BSAFE 安全漏洞 — Dell BSAFE Crypto-JCWE-1329 9.1 Critical2024-02-02
CVE-2024-1047 ThemeIsle SDK <= Various Versions - Missing Authorization — Menu Icons by ThemeIsleCWE-862 5.3 Medium2024-02-02
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-352 4.3 Medium2024-02-02

Vulnerabilities classified as access:pre-auth represent 18946 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.