CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,572 vulnerabilities with CWE-639
CVE-2025-49352
MEDIUM
YoOhw Studio Order Cancellation & Returns for WooCommerce - Auth By...
CVSS 4.3
CVE-2025-49334
MEDIUM
MyD Delivery <1.3.7 - Auth Bypass
CVSS 5.3
CVE-2025-63053
MEDIUM
Jewel Theme Master Addons for Elementor <2.0.9.9.4 - Auth Bypass
CVSS 5.3
CVE-2025-69032
MEDIUM
Qodeinteractive Fivestar < 1.7 - IDOR
CVSS 5.4
CVE-2025-69030
MEDIUM
Qodeinteractive Backpack Traveler < 2.10.3 - IDOR
CVSS 5.4
CVE-2025-69029
MEDIUM
Select-Themes Struktur <2.5.1 - Auth Bypass
CVSS 5.4
CVE-2025-68997
MEDIUM
wpDiscuz <7.6.40 - Auth Bypass
CVSS 5.3
CVE-2025-68979
MEDIUM
SimpleCalendar Google Calendar Events <3.5.9 - Auth Bypass
CVSS 5.3
CVE-2025-68975
MEDIUM
Eagle-Themes Eagle Booking <1.3.4.3 - Auth Bypass
CVSS 4.3
CVE-2025-68502
MEDIUM
Crocoblock JetPopup <2.0.20.1 - Auth Bypass
CVSS 4.3
CVE-2025-69202
MEDIUM
Axios Cache Interceptor <1.11.1 - Auth Bypass
CVSS 6.5
CVE-2025-15106
MEDIUM
Maxun < 0.0.28 - Improper Authorization
CVSS 6.3
CVE-2025-67909
HIGH
WP Swings Membership For WooCommerce <= 3.0.3 - Auth Bypass
CVSS 7.5
CVE-2025-7733
MEDIUM
WP JobHunt <7.7 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-66911
MEDIUM
Turms - Improper Access Control
CVSS 6.5
CVE-2025-14882
LOW
Pypi Pretix < 2025.10.1 - IDOR
CVE-2025-14881
LOW
Pypi Pretix < 2025.10.1 - IDOR
CVE-2025-64282
MEDIUM
RadiusTheme Radius Blocks <2.2.1 - Auth Bypass
CVSS 4.3
CVE-2025-63043
MEDIUM
PickPlugins Post Grid & Gutenberg Blocks <2.3.19 - Auth Bypass
CVSS 5.3
CVE-2025-1031
HIGH
SoliClub <5.3.7 - Auth Bypass
CVSS 7.5
CVE-2025-13110
MEDIUM
HUSKY - Products Filter Professional - Insecure Direct Object Refer...
CVSS 4.3
CVE-2025-10910
CRITICAL
Govee Cloud - RCE
CVE-2025-10019
MEDIUM
Contact Form Email <1.3.60 - Auth Bypass
CVSS 6.5
CVE-2025-34438
HIGH
Wwbn Avideo < 20.0 - IDOR
CVSS 8.1
CVE-2025-34437
HIGH
Wwbn Avideo < 20.0 - IDOR
CVSS 8.8
Details
Vulnerabilities
1,572
Exploit Likelihood
High