The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,804 vulnerabilities with CWE-862
CVE-2026-62194
HIGH
OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
CVSS 8.8
CVE-2026-62191
HIGH
OpenClaw 2026.6.6 < 2026.6.8 Authorization Bypass via Message Mutations
CVSS 7.1
CVE-2026-62186
HIGH
OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override
CVSS 7.6
CVE-2026-58410
HIGH
ChurchCRM < 7.4.0 - Authenticated Family Record Access Control Bypass
CVSS 7.1
CVE-2026-58408
MEDIUM
ChurchCRM < 7.4.0 CSVCreateFile.php - Unauthorized Member PII Export
CVSS 6.5
CVE-2026-9824
MEDIUM
Mattermost - Remote Cluster Metadata Enumeration via /share-channel Autocomplete
CVSS 4.3
CVE-2026-9820
LOW
Mattermost schemes teams endpoint exposes private team invite IDs
CVSS 3.8
CVE-2026-14934
CRITICAL
Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
CVE-2026-61985
MEDIUM
WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-61983
MEDIUM
WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-61968
MEDIUM
WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-61958
MEDIUM
WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability
CVSS 5.4
CVE-2026-61952
MEDIUM
WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability
CVSS 4.9
CVE-2026-59523
MEDIUM
WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57812
MEDIUM
WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57797
MEDIUM
WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57782
MEDIUM
WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57781
MEDIUM
WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57779
MEDIUM
WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57778
MEDIUM
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57776
MEDIUM
WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57774
MEDIUM
WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57740
HIGH
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57729
HIGH
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57727
HIGH
WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
CVSS 7.5
Details
Vulnerabilities
8,804
Exploit Likelihood
High