The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,804 vulnerabilities with CWE-862
CVE-2026-57705
HIGH
WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57424
MEDIUM
WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57419
MEDIUM
WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57418
MEDIUM
WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57412
MEDIUM
WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57408
MEDIUM
WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57406
MEDIUM
WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57405
HIGH
WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57404
MEDIUM
WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57400
MEDIUM
WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57395
MEDIUM
WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57392
MEDIUM
WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57390
MEDIUM
WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57378
HIGH
WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57377
MEDIUM
WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57375
MEDIUM
WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-10085
MEDIUM
Ordinary group/direct message member can enable group_constrained and remove all channel participants
CVSS 5.4
CVE-2026-57830
CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion < 2.2.7
CVSS 9.1
CVE-2026-15541
HIGH
will-moss Isaiah Master Websocket server.go Server.Handle authorization
CVSS 7.3
CVE-2026-15507
MEDIUM
coollabsio Coolify Policy Policies authorization
CVSS 6.3
CVE-2026-61442
HIGH
PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH
CVSS 7.1
CVE-2026-9017
MEDIUM
Webaways NEX-Forms <= 9.2.2 - Unauthenticated Form Entry Email Modification
CVSS 5.3
CVE-2026-12994
MEDIUM
Wcfm – Frontend Manager For WooCommerce < 6.7.27 - Authorization Bypass
CVSS 5.3
CVE-2026-12738
MEDIUM
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
CVSS 4.3
CVE-2026-12103
MEDIUM
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
CVSS 4.3
Details
Vulnerabilities
8,804
Exploit Likelihood
High