The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,331 vulnerabilities with CWE-862
CVE-2025-49988
MEDIUM
Renzo Contact Form 7 AWeber Extension <0.1.38 - Info Disclosure
CVSS 5.3
CVE-2025-49987
MEDIUM
WPFactory CRM ERP Business Solution <1.13 - Info Disclosure
CVSS 5.3
CVE-2025-49986
MEDIUM
Video List Manager <= 1.7 - Missing Authorization
CVSS 5.3
CVE-2025-49982
MEDIUM
Aguilatechnologies WP Customer Area <8.2.5 - Info Disclosure
CVSS 4.3
CVE-2025-49981
MEDIUM
mahabub81 User Roles and Capabilities <1.2.6 - RCE
CVSS 4.3
CVE-2025-49980
MEDIUM
WP User Profile Avatar <1.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-49979
MEDIUM
slui Media Hygiene <4.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-49976
MEDIUM
WANotifier <2.7.7 - Info Disclosure
CVSS 4.3
CVE-2025-49974
MEDIUM
UpStream: a Project Management Plugin for WordPress <= 2.1.1 - Missing Authorization
CVSS 4.3
CVE-2025-49973
MEDIUM
GrandPlugins Image Sizes <1.0.10 - RCE
CVSS 4.3
CVE-2025-49971
MEDIUM
aThemeArt Translations eDS Responsive Menu <1.2 - Info Disclosure
CVSS 4.3
CVE-2025-49970
MEDIUM
Hello FSE Blog <1.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-49969
MEDIUM
Zara 4 Image Compression <1.2.17.2 - RCE
CVSS 4.3
CVE-2025-6341
MEDIUM
School Fees Payment System 1.0 - CSRF
CVSS 4.3
CVE-2025-6284
MEDIUM
PHPGurukul Car Rental Portal 3.0 - CSRF
CVSS 4.3
CVE-2025-4571
MEDIUM
GiveWP - Donation Plugin and Fundraising Platform <= 4.3.0 - Authenticated Missing Authorization in Permissions Check
CVSS 5.4
CVE-2025-23999
MEDIUM
Cloudways Breeze <= 2.2.13 - Missing Authorization
CVSS 4.3
CVE-2025-1562
CRITICAL
FunnelKit Automations < 3.5.3 - Unauthenticated Arbitrary Plugin Installation via install_or_activate_addon_plugins
CVSS 9.8
CVE-2025-49880
MEDIUM
CubeWP Forms <= 1.1.5 - Missing Authorization
CVSS 4.3
CVE-2025-49874
MEDIUM
Arconix FAQ <1.9.6 - Info Disclosure
CVSS 4.3
CVE-2025-49872
MEDIUM
WPExperts.io myCred <2.9.4.2 - Info Disclosure
CVSS 5.3
CVE-2025-49864
MEDIUM
AFS Analytics <4.21 - Info Disclosure
CVSS 5.3
CVE-2025-49857
MEDIUM
WPExperts.io myCred <2.9.4.2 - Info Disclosure
CVSS 4.3
CVE-2025-49234
MEDIUM
WP Dummy Content Generator <3.4.6 - Info Disclosure
CVSS 6.5
CVE-2025-6106
MEDIUM
WukongCRM 9.0 - Cross-Site Request Forgery in AdminRoleController.java
CVSS 4.3
Details
Vulnerabilities
8,331
Exploit Likelihood
High