Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18835

18835 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-13521 WP Status Notifier <= 1.0 - Cross-Site Request Forgery to Settings Update — WP Status NotifierCWE-352 4.3 Medium2026-01-07
CVE-2025-15018 Optional Email <= 1.3.11 - Unauthenticated Privilege Escalation to Account Takeover — Optional EmailCWE-639 9.8 Critical2026-01-07
CVE-2025-13493 Latest Registered Users <= 1.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via User Data Export — Latest Registered UsersCWE-862 7.5 High2026-01-07
CVE-2025-13520 MTCaptcha WordPress Plugin <= 2.7.2 - Cross-Site Request Forgery to Settings Update — MTCaptcha WordPress PluginCWE-352 4.3 Medium2026-01-07
CVE-2025-13527 xShare <= 1.0.1 - Cross-Site Request Forgery to 'rs_plugin_reset' Parameter — xShareCWE-352 4.3 Medium2026-01-07
CVE-2025-13529 Unify <= 3.4.9 - Missing Authorization to Unauthenticated Option Deletion via 'unify_plugin_downgrade' Parameter — UnifyCWE-862 5.3 Medium2026-01-07
CVE-2025-12540 ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure — ShareThis Dashboard for Google AnalyticsCWE-200 4.7 Medium2026-01-07
CVE-2025-14999 Latest Tabs <= 1.5 - Cross-Site Request Forgery to Plugin's Settings Update — Latest TabsCWE-352 4.3 Medium2026-01-07
CVE-2025-13519 SVG Map Plugin <= 1.0.0 - Cross-Site Request Forgery to Settings Update and Stored Cross-Site Scripting — SVG Map by SmjrifleCWE-352 6.1 Medium2026-01-07
CVE-2025-11877 User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login — User Activity LogCWE-862 7.5 High2026-01-07
CVE-2025-13369 Premmerce WooCommerce Customers Manager <= 1.1.14 - Reflected Cross-Site Scripting — Premmerce WooCommerce Customers ManagerCWE-79 6.1 Medium2026-01-07
CVE-2025-31963 HCL BigFix IVR is impacted by improper authentication and missing CSRF protection — BigFix IVRCWE-306 2.9 Low2026-01-07
CVE-2025-14842 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload — Drag and Drop Multiple File Upload for Contact Form 7CWE-434 6.1 Medium2026-01-07
CVE-2025-13371 Money Space <= 2.13.9 - Unauthenticated Sensitive Information Exposure — Money SpaceCWE-200 8.6 High2026-01-07
CVE-2026-0656 iPaymu Payment Gateway for WooCommerce <= 2.0.2 - Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure — iPaymu Payment Gateway for WooCommerceCWE-862 8.2 High2026-01-07
CVE-2025-14845 NS IE Compatibility Fixer <= 2.1.5 - Cross-Site Request Forgery to Plugin Settings Update — NS Ie Compatibility FixerCWE-352 4.3 Medium2026-01-07
CVE-2025-13657 HelpDesk contact form plugin <= 1.1.5 - Cross-Site Request Forgery to Settings Update via handle_query_args — HelpDesk Contact FormCWE-352 4.3 Medium2026-01-07
CVE-2025-14875 HBLPAY Payment Gateway for WooCommerce <= 5.0.0 - Reflected Cross-Site Scripting via 'cusdata' Parameter — HBLPAY Payment Gateway for WooCommerceCWE-79 6.1 Medium2026-01-07
CVE-2025-14901 Bit Form – Contact Form Plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay — Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builderCWE-862 6.5 Medium2026-01-07
CVE-2025-14904 Newsletter Email Subscribe <= 2.4 - Cross-Site Request Forgery to Plugin Settings Update — Newsletter Email SubscribeCWE-352 4.3 Medium2026-01-07
CVE-2025-14835 WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting — WP Photo Album PlusCWE-80 7.1 High2026-01-07
CVE-2025-15474 AuntyFey Smart Combination Lock BLE Connection Flood DoS — AuntyFey Smart Combination LockCWE-770 6.5 -2026-01-07
CVE-2025-14468 AMP for WP – Accelerated Mobile Pages <= 1.1.9 - Cross-Site Request Forgery to Comment Submission — AMP for WP – Accelerated Mobile PagesCWE-352 4.3 Medium2026-01-07
CVE-2025-14891 Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter — Customer Reviews for WooCommerceCWE-79 6.4 Medium2026-01-07
CVE-2025-12648 WP-Members Membership Plugin <= 3.5.4.4 - Unauthenticated Information Exposure via Unprotected Files — WP-Members Membership PluginCWE-552 5.3 Medium2026-01-07
CVE-2020-36921 RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability — RED-V Super Digital Signage System RXV-A740RCWE-548 7.5 High2026-01-06
CVE-2020-36922 Sony BRAVIA Digital Signage 1.7.8 Unauthenticated System API Information Disclosure — Sony BRAVIA Digital SignageCWE-497 7.5 High2026-01-06
CVE-2020-36915 Adtec Digital SignEdje Digital Signage Player v2.08.28 Default Credentials — SignEdje Digital Signage PlayerCWE-798 7.5 High2026-01-06
CVE-2020-36907 Extreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service — Aerohive HiveOSCWE-770 7.5 High2026-01-06
CVE-2025-9637 Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862 6.5 Medium2026-01-06

Vulnerabilities classified as access:pre-auth represent 18835 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.