CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,804 vulnerabilities with CWE-862
CVE-2026-57705 HIGH
WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57424 MEDIUM
WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57419 MEDIUM
WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57418 MEDIUM
WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57412 MEDIUM
WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57408 MEDIUM
WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57406 MEDIUM
WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57405 HIGH
WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57404 MEDIUM
WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57400 MEDIUM
WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57395 MEDIUM
WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57392 MEDIUM
WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57390 MEDIUM
WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57378 HIGH
WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57377 MEDIUM
WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57375 MEDIUM
WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-10085 MEDIUM
Ordinary group/direct message member can enable group_constrained and remove all channel participants
CVSS 5.4
CVE-2026-57830 CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion < 2.2.7
CVSS 9.1
CVE-2026-15541 HIGH
will-moss Isaiah Master Websocket server.go Server.Handle authorization
CVSS 7.3
CVE-2026-15507 MEDIUM
coollabsio Coolify Policy Policies authorization
CVSS 6.3
CVE-2026-61442 HIGH
PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH
CVSS 7.1
CVE-2026-9017 MEDIUM
Webaways NEX-Forms <= 9.2.2 - Unauthenticated Form Entry Email Modification
CVSS 5.3
CVE-2026-12994 MEDIUM
Wcfm – Frontend Manager For WooCommerce < 6.7.27 - Authorization Bypass
CVSS 5.3
CVE-2026-12738 MEDIUM
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
CVSS 4.3
CVE-2026-12103 MEDIUM
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
CVSS 4.3
Details
Vulnerabilities 8,804
Exploit Likelihood High