CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-57991 MEDIUM
Clariti <= 1.2.1 - Missing Authorization
CVSS 5.4
CVE-2025-57990 MEDIUM
solwininfotech Blog Designer <3.1.8 - Info Disclosure
CVSS 5.4
CVE-2025-57987 MEDIUM
ThimPress WP Events Manager <2.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-57985 MEDIUM
MantraBrain Ultimate Watermark <1.1 - RCE
CVSS 4.3
CVE-2025-57976 MEDIUM
CardCom Payment Gateway <3.5.0.4 - Info Disclosure
CVSS 5.3
CVE-2025-57975 MEDIUM
RadiusTheme Team <5.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-57972 MEDIUM
WPFactory Helpdesk <2.0.2 - Info Disclosure
CVSS 4.3
CVE-2025-57971 MEDIUM
SALESmanago & Leadoo <3.8.1 - Info Disclosure
CVSS 5.3
CVE-2025-57969 MEDIUM
Hide WP Toolbar <= 2.7 - Missing Authorization
CVSS 4.3
CVE-2025-57961 MEDIUM
CoDesigner <= 4.29 - Missing Authorization
CVSS 4.3
CVE-2025-57957 MEDIUM
WooMS <= 9.12 - Missing Authorization
CVSS 5.3
CVE-2025-57955 MEDIUM
Plugin Devs Post Carousel Slider <1.7.0 - Info Disclosure
CVSS 6.5
CVE-2025-57949 MEDIUM
Ongkoskirim.id <1.0.6 - Info Disclosure
CVSS 5.4
CVE-2025-57944 MEDIUM
Skimlinks Affiliate Marketing Tool <1.3 - Info Disclosure
CVSS 5.3
CVE-2025-57939 MEDIUM
Blocksera Image Hover Effects - Elementor Addon <1.4.4 - RCE
CVSS 5.3
CVE-2025-57936 MEDIUM
Subresource Integrity (SRI) Manager <= 0.4.0 - Missing Authorization
CVSS 4.3
CVE-2025-57921 MEDIUM
N-Media Frontend File Manager <23.2 - RCE
CVSS 5.3
CVE-2025-57917 MEDIUM
Printcart Web to Print Product Designer for WooCommerce <2.4.3 - Pr...
CVSS 4.3
CVE-2025-57909 MEDIUM
Editor Custom Color Palette <3.4.8 - Auth Bypass
CVSS 6.5
CVE-2025-57907 MEDIUM
Heureka Group Heureka <= 1.1.0 - Missing Authorization
CVSS 5.3
CVE-2025-57899 MEDIUM
AresIT WP Compress <6.50.54 - Info Disclosure
CVSS 5.3
CVE-2025-53452 MEDIUM
Barry Event Rocket <3.3 - Info Disclosure
CVSS 4.3
CVE-2025-59413 MEDIUM
CubeCart < 6.5.11 - Unauthenticated Newsletter Subscription Tampering via Force Unsubscribe Parameter
CVSS 6.5
CVE-2025-57605 HIGH
AiKaan IoT Platform - Privilege Escalation
CVSS 8.8
CVE-2025-10489 MEDIUM
WordPress SureForms <1.12.0 - Privilege Escalation
CVSS 4.3
Details
Vulnerabilities 8,330
Exploit Likelihood High