access:pre-auth 类型相关 24858 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-0865 | WordPress plugin WP Media Category Management 跨站请求伪造漏洞 — WP Media Category Management CWE-352 | 6.5 | Medium | 2025-02-19 |
| CVE-2025-1441 | WordPress plugin Royal Elementor Addons and Templates 跨站请求伪造漏洞 — Royal Addons for Elementor – Addons and Templates Kit for Elementor CWE-352 | 6.1 | Medium | 2025-02-19 |
| CVE-2024-11582 | WordPress plugin Subscribe2 跨站脚本漏洞 — Subscribe2 – Form, Email Subscribers & Newsletters CWE-79 | 7.2 | High | 2025-02-19 |
| CVE-2024-13508 | WordPress plugin Booking Package 跨站脚本漏洞 — Booking Package CWE-79 | 6.1 | Medium | 2025-02-18 |
| CVE-2025-25284 | ZOO-Project 路径遍历漏洞 — ZOO-Project CWE-22 | 6.2 | - | 2025-02-18 |
| CVE-2025-0817 | WordPress plugin FormCraft 跨站脚本漏洞 — FormCraft CWE-79 | 7.2 | High | 2025-02-18 |
| CVE-2024-13681 | WordPress plugin Uncode 输入验证错误漏洞 — Uncode CWE-20 | 7.5 | High | 2025-02-18 |
| CVE-2025-0521 | WordPress plugin Post SMTP 跨站脚本漏洞 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App CWE-79 | 7.2 | High | 2025-02-18 |
| CVE-2024-13797 | WordPress plugin PressMart 代码注入漏洞 — PressMart - Modern Elementor WooCommerce WordPress Theme CWE-94 | 7.3 | High | 2025-02-18 |
| CVE-2024-13718 | WordPress plugin Flexible Wishlist for WooCommerce 跨站请求伪造漏洞 — Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later CWE-352 | 4.3 | Medium | 2025-02-18 |
| CVE-2024-12860 | WordPress plugin CarSpot 安全漏洞 — CarSpot – Dealership Wordpress Classified Theme CWE-620 | 9.8 | Critical | 2025-02-18 |
| CVE-2024-13316 | WordPress plugin Scratch & Win 安全漏洞 — Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more CWE-862 | 5.3 | Medium | 2025-02-18 |
| CVE-2025-0423 | Cordaware bestinformed 安全漏洞 — bestinformed Web CWE-20 | 6.1 | - | 2025-02-18 |
| CVE-2025-0864 | WordPress plugin Active Products Tables for WooCommerce 跨站脚本漏洞 — Active Products Tables for WooCommerce. Use constructor to create tables CWE-79 | 6.1 | Medium | 2025-02-18 |
| CVE-2024-13795 | WordPress plugin Ecwid by Lightspeed Ecommerce Shopping Cart 跨站请求伪造漏洞 — Ecwid by Lightspeed Ecommerce Shopping Cart CWE-352 | 4.3 | Medium | 2025-02-18 |
| CVE-2024-13704 | WordPress plugin Super Testimonials 安全漏洞 — Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress CWE-80 | 7.2 | High | 2025-02-18 |
| CVE-2024-11376 | WordPress plugin s2Member 跨站脚本漏洞 — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions CWE-79 | 6.1 | Medium | 2025-02-18 |
| CVE-2024-13523 | WordPress plugin MemorialDay 跨站请求伪造漏洞 — MemorialDay CWE-352 | 6.1 | Medium | 2025-02-18 |
| CVE-2024-13315 | WordPress plugin Shopwarden 跨站请求伪造漏洞 — Shopwarden – Automated WooCommerce monitoring & testing CWE-352 | 8.8 | High | 2025-02-18 |
| CVE-2024-13438 | WordPress plugin SpeedSize Image & Video AI-Optimizer 跨站请求伪造漏洞 — SpeedSize Image & Video AI-Optimizer CWE-352 | 4.3 | Medium | 2025-02-18 |
| CVE-2024-13556 | WordPress plugin Affiliate Links 安全漏洞 — Affiliate Links – Link Cloaking and Management CWE-862 | 8.1 | High | 2025-02-18 |
| CVE-2024-13609 | WordPress plugin 1 Click WordPress Migration Plugin 信息泄露漏洞 — 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone CWE-200 | 5.9 | Medium | 2025-02-18 |
| CVE-2024-13555 | WordPress plugin 1 Click WordPress Migration Plugin 跨站请求伪造漏洞 — 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone CWE-352 | 5.3 | Medium | 2025-02-18 |
| CVE-2024-13622 | WordPress plugin File Uploads Addon for WooCommerce 信息泄露漏洞 — File Uploads Addon for WooCommerce CWE-200 | 7.5 | High | 2025-02-18 |
| CVE-2024-12314 | WordPress plugin Rapid Cache 安全漏洞 — Rapid Cache CWE-524 | 7.2 | High | 2025-02-18 |
| CVE-2024-13535 | WordPress plugin Actionwear products sync 安全漏洞 — Actionwear products sync CWE-209 | 5.3 | Medium | 2025-02-18 |
| CVE-2024-13725 | WordPress plugin Keap Official Opt-in Forms 路径遍历漏洞 — Keap Official Opt-in Forms CWE-22 | 9.8 | Critical | 2025-02-18 |
| CVE-2024-13540 | WordPress plugin WooODT Lite 安全漏洞 — WooODT Lite – Delivery & pickup date time location for WooCommerce CWE-209 | 5.3 | Medium | 2025-02-18 |
| CVE-2024-13852 | WordPress plugin Option Editor 跨站请求伪造漏洞 — Option Editor CWE-352 | 8.8 | High | 2025-02-18 |
| CVE-2025-0796 | WordPress plugin Mortgage Lead Capture System 跨站请求伪造漏洞 — WPrequal CWE-352 | 4.3 | Medium | 2025-02-18 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24858 条 CVE 漏洞。