CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,332 vulnerabilities with CWE-862
CVE-2025-39456 MEDIUM
iTRON WP Logger <2.2 - Info Disclosure
CVSS 5.4
CVE-2025-32620 HIGH
fromdoppler Doppler Forms <2.4.5 - Info Disclosure
CVSS 7.1
CVE-2025-32593 HIGH
Bytes Technolab Add Product Frontend - Auth Bypass
CVSS 8.2
CVE-2025-32544 HIGH
The Right Software WooCommerce Loyal Customers <2.6 - Info Disclosure
CVSS 7.5
CVE-2025-27310 MEDIUM
Radius of Thought Page and Post Lister <1.2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-26968 HIGH
Cloak Front End Email <1.9.5 - Info Disclosure
CVSS 7.5
CVE-2025-24737 MEDIUM
Mat Bao Corporation WP Helper Premium <4.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-24583 MEDIUM
AA Web Servant <3.16.5 - Info Disclosure
CVSS 6.5
CVE-2025-24581 MEDIUM
Themefic Instantio <3.3.7 - Info Disclosure
CVSS 6.5
CVE-2025-24577 MEDIUM
Poll Maker <= 5.5.0 - Missing Authorization
CVSS 6.5
CVE-2025-23958 MEDIUM
FADI MED Editor Wysiwyg Background Color <1.0 - Info Disclosure
CVSS 6.5
CVE-2025-23906 MEDIUM
WordPress Dashboard Tweeter <1.3.2 - RCE
CVSS 6.5
CVE-2025-23773 MEDIUM
mingocommerce Delete All Posts <= 1.1.1 - Missing Authorization
CVSS 6.5
CVE-2025-31338 MEDIUM
Wisdom Master Pro <5.3 - Info Disclosure
CVE-2025-39602 MEDIUM
WC Product Table <3.9.5 - Info Disclosure
CVSS 4.3
CVE-2025-39591 MEDIUM
WP Shuffle WP Subscription Forms <1.2.3 - Info Disclosure
CVSS 5.4
CVE-2025-39571 MEDIUM
WPXPO WowStore <4.2.4 - Info Disclosure
CVSS 4.3
CVE-2025-39560 MEDIUM
Shahjada Live Forms <4.8.4 - Info Disclosure
CVSS 5.4
CVE-2025-39552 MEDIUM
Dylan James Zephyr Project Manager <3.3.200 - Info Disclosure
CVSS 5.4
CVE-2025-39545 MEDIUM
miniOrange WordPress REST API Authentication <= 3.6.3 - Missing Authorization
CVSS 5.4
CVE-2025-39531 MEDIUM
Slazzer Background Changer <3.14 - Info Disclosure
CVSS 5.3
CVE-2025-39522 MEDIUM
Sebastian Lee Dynamic Post <4.10 - Info Disclosure
CVSS 5.4
CVE-2025-39513 MEDIUM
ActiveDEMAND <= 0.2.46 - Missing Authorization
CVSS 5.3
CVE-2025-3687 MEDIUM
misstt123 oasys 1.0 - Cross-Site Request Forgery in Sticky Notes Handler
CVSS 4.3
CVE-2025-30960 HIGH
NotFound FS Poster <6.5.8 - Info Disclosure
CVSS 8.3
Details
Vulnerabilities 8,332
Exploit Likelihood High