The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,330 vulnerabilities with CWE-862
CVE-2025-7821
MEDIUM
WC Plus <= 1.2.0 - Unauthenticated Data Modification via pluswc_logo_favicon_logo_base AJAX Action
CVSS 5.3
CVE-2025-55741
HIGH
UnoPim < 0.3.1 - Unauthenticated Improper Access Control via Mass-Delete Endpoint
CVSS 8.1
CVE-2025-9331
MEDIUM
Spacious WordPress <1.9.11 - Info Disclosure
CVSS 4.3
CVE-2025-57896
MEDIUM
Church Admin <= 5.0.26 - Missing Authorization
CVSS 5.3
CVE-2025-57894
MEDIUM
WPPizza <= 3.19.8 - Missing Authorization
CVSS 4.3
CVE-2025-57884
MEDIUM
wpsoul Greenshift <12.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-52352
CRITICAL
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 - Auth Bypass
CVSS 9.8
CVE-2025-54040
MEDIUM
Webba Booking <5.1.20 - Info Disclosure
CVSS 6.5
CVE-2025-54025
MEDIUM
RelyWP Coupon Affiliates <6.4.0 - Info Disclosure
CVSS 6.5
CVE-2025-49406
HIGH
Houzez < 4.1.1 - Missing Authorization
CVSS 8.5
CVE-2025-49396
MEDIUM
Themify Builder <= 7.6.7 - Missing Authorization
CVSS 4.3
CVE-2025-9202
MEDIUM
ColorMag <= 4.0.19 - Authenticated Arbitrary Plugin Installation via Missing Capability Check
CVSS 4.3
CVE-2025-55734
MEDIUM
flaskblog < 2.8.0 - Missing Authorization in Admin Subroutes
CVSS 6.5
CVE-2025-4046
HIGH
Lexmark Cloud Services - Info Disclosure
CVSS 8.5
CVE-2025-8357
MEDIUM
Media Library Assistant <3.27 - Path Traversal
CVSS 4.3
CVE-2025-7499
MEDIUM
BetterDocs <4.1.1 - Info Disclosure
CVSS 5.3
CVE-2025-8898
CRITICAL
Taxi Booking Manager <1.3.0 - Privilege Escalation
CVSS 9.8
CVE-2025-7664
HIGH
AL Pack plugin for WordPress <1.0.2 - Auth Bypass
CVSS 7.5
CVE-2025-8996
MEDIUM
Layout Builder Advanced Permissions < 2.2.0 - Missing Authorization
CVSS 4.3
CVE-2025-8361
HIGH
Drupal Config Pages < 2.18.0 - Missing Authorization
CVSS 7.6
CVE-2025-49432
MEDIUM
FWDesign Ultimate Video Player <10.1 - RCE
CVSS 5.3
CVE-2025-8342
HIGH
WooCommerce OTP Login With Phone Number, OTP Verification <1.8.47 -...
CVSS 8.1
CVE-2025-8992
MEDIUM
mtons mblog < 3.5.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-55716
MEDIUM
VeronaLabs WP Statistics <14.15 - RCE
CVSS 4.3
CVE-2025-55712
MEDIUM
POSIMYTH The Plus Addons for Elementor Page Builder Lite <6.3.13 - ...
CVSS 6.5
Details
Vulnerabilities
8,330
Exploit Likelihood
High