The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,807 vulnerabilities with CWE-862
CVE-2026-12994
MEDIUM
Wcfm – Frontend Manager For WooCommerce < 6.7.27 - Authorization Bypass
CVSS 5.3
CVE-2026-12738
MEDIUM
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
CVSS 4.3
CVE-2026-12103
MEDIUM
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
CVSS 4.3
CVE-2026-7620
MEDIUM
Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action
CVSS 4.3
CVE-2026-7559
MEDIUM
Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
CVSS 4.3
CVE-2026-6804
MEDIUM
AI Copilot – Content Generator < 1.4.12 - Authorization Bypass
CVSS 5.3
CVE-2026-6803
MEDIUM
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
CVSS 5.3
CVE-2026-3552
MEDIUM
SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action
CVSS 4.3
CVE-2026-1832
MEDIUM
ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion
CVSS 4.3
CVE-2026-13250
MEDIUM
Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action
CVSS 5.3
CVE-2026-8678
MEDIUM
MyParcel < 4.25.1 - Authorization Bypass
CVSS 4.3
CVE-2026-10628
MEDIUM
Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
CVSS 4.3
CVE-2026-58590
MEDIUM
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
CVSS 5.4
CVE-2026-58589
MEDIUM
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
CVSS 5.4
CVE-2026-49394
HIGH
Frappe: Auth. bypass via update_page
CVE-2026-48127
MEDIUM
Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
CVE-2026-47422
MEDIUM
Frappe: Unrestricted API access to save_report
CVE-2026-13241
MEDIUM
Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
CVSS 6.5
CVE-2026-13240
MEDIUM
Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
CVSS 6.5
CVE-2026-13239
MEDIUM
WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
CVSS 6.5
CVE-2026-13236
MEDIUM
AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
CVSS 4.2
CVE-2026-13235
LOW
AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
CVSS 3.3
CVE-2026-11909
LOW
Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
CVSS 3.3
CVE-2026-10768
CRITICAL
LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
CVSS 9.8
CVE-2026-57221
MEDIUM
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
CVSS 5.0
Details
Vulnerabilities
8,807
Exploit Likelihood
High