CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-7821 MEDIUM
WC Plus <= 1.2.0 - Unauthenticated Data Modification via pluswc_logo_favicon_logo_base AJAX Action
CVSS 5.3
CVE-2025-55741 HIGH
UnoPim < 0.3.1 - Unauthenticated Improper Access Control via Mass-Delete Endpoint
CVSS 8.1
CVE-2025-9331 MEDIUM
Spacious WordPress <1.9.11 - Info Disclosure
CVSS 4.3
CVE-2025-57896 MEDIUM
Church Admin <= 5.0.26 - Missing Authorization
CVSS 5.3
CVE-2025-57894 MEDIUM
WPPizza <= 3.19.8 - Missing Authorization
CVSS 4.3
CVE-2025-57884 MEDIUM
wpsoul Greenshift <12.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-52352 CRITICAL
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 - Auth Bypass
CVSS 9.8
CVE-2025-54040 MEDIUM
Webba Booking <5.1.20 - Info Disclosure
CVSS 6.5
CVE-2025-54025 MEDIUM
RelyWP Coupon Affiliates <6.4.0 - Info Disclosure
CVSS 6.5
CVE-2025-49406 HIGH
Houzez < 4.1.1 - Missing Authorization
CVSS 8.5
CVE-2025-49396 MEDIUM
Themify Builder <= 7.6.7 - Missing Authorization
CVSS 4.3
CVE-2025-9202 MEDIUM
ColorMag <= 4.0.19 - Authenticated Arbitrary Plugin Installation via Missing Capability Check
CVSS 4.3
CVE-2025-55734 MEDIUM
flaskblog < 2.8.0 - Missing Authorization in Admin Subroutes
CVSS 6.5
CVE-2025-4046 HIGH
Lexmark Cloud Services - Info Disclosure
CVSS 8.5
CVE-2025-8357 MEDIUM
Media Library Assistant <3.27 - Path Traversal
CVSS 4.3
CVE-2025-7499 MEDIUM
BetterDocs <4.1.1 - Info Disclosure
CVSS 5.3
CVE-2025-8898 CRITICAL
Taxi Booking Manager <1.3.0 - Privilege Escalation
CVSS 9.8
CVE-2025-7664 HIGH
AL Pack plugin for WordPress <1.0.2 - Auth Bypass
CVSS 7.5
CVE-2025-8996 MEDIUM
Layout Builder Advanced Permissions < 2.2.0 - Missing Authorization
CVSS 4.3
CVE-2025-8361 HIGH
Drupal Config Pages < 2.18.0 - Missing Authorization
CVSS 7.6
CVE-2025-49432 MEDIUM
FWDesign Ultimate Video Player <10.1 - RCE
CVSS 5.3
CVE-2025-8342 HIGH
WooCommerce OTP Login With Phone Number, OTP Verification <1.8.47 -...
CVSS 8.1
CVE-2025-8992 MEDIUM
mtons mblog < 3.5.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-55716 MEDIUM
VeronaLabs WP Statistics <14.15 - RCE
CVSS 4.3
CVE-2025-55712 MEDIUM
POSIMYTH The Plus Addons for Elementor Page Builder Lite <6.3.13 - ...
CVSS 6.5
Details
Vulnerabilities 8,330
Exploit Likelihood High