CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,807 vulnerabilities with CWE-862
CVE-2026-12994 MEDIUM
Wcfm – Frontend Manager For WooCommerce < 6.7.27 - Authorization Bypass
CVSS 5.3
CVE-2026-12738 MEDIUM
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
CVSS 4.3
CVE-2026-12103 MEDIUM
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
CVSS 4.3
CVE-2026-7620 MEDIUM
Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action
CVSS 4.3
CVE-2026-7559 MEDIUM
Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
CVSS 4.3
CVE-2026-6804 MEDIUM
AI Copilot – Content Generator < 1.4.12 - Authorization Bypass
CVSS 5.3
CVE-2026-6803 MEDIUM
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
CVSS 5.3
CVE-2026-3552 MEDIUM
SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action
CVSS 4.3
CVE-2026-1832 MEDIUM
ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion
CVSS 4.3
CVE-2026-13250 MEDIUM
Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action
CVSS 5.3
CVE-2026-8678 MEDIUM
MyParcel < 4.25.1 - Authorization Bypass
CVSS 4.3
CVE-2026-10628 MEDIUM
Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
CVSS 4.3
CVE-2026-58590 MEDIUM
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
CVSS 5.4
CVE-2026-58589 MEDIUM
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
CVSS 5.4
CVE-2026-49394 HIGH
Frappe: Auth. bypass via update_page
CVE-2026-48127 MEDIUM
Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
CVE-2026-47422 MEDIUM
Frappe: Unrestricted API access to save_report
CVE-2026-13241 MEDIUM
Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
CVSS 6.5
CVE-2026-13240 MEDIUM
Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
CVSS 6.5
CVE-2026-13239 MEDIUM
WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
CVSS 6.5
CVE-2026-13236 MEDIUM
AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
CVSS 4.2
CVE-2026-13235 LOW
AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
CVSS 3.3
CVE-2026-11909 LOW
Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
CVSS 3.3
CVE-2026-10768 CRITICAL
LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
CVSS 9.8
CVE-2026-57221 MEDIUM
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
CVSS 5.0
Details
Vulnerabilities 8,807
Exploit Likelihood High