The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,332 vulnerabilities with CWE-862
CVE-2025-39456
MEDIUM
iTRON WP Logger <2.2 - Info Disclosure
CVSS 5.4
CVE-2025-32620
HIGH
fromdoppler Doppler Forms <2.4.5 - Info Disclosure
CVSS 7.1
CVE-2025-32593
HIGH
Bytes Technolab Add Product Frontend - Auth Bypass
CVSS 8.2
CVE-2025-32544
HIGH
The Right Software WooCommerce Loyal Customers <2.6 - Info Disclosure
CVSS 7.5
CVE-2025-27310
MEDIUM
Radius of Thought Page and Post Lister <1.2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-26968
HIGH
Cloak Front End Email <1.9.5 - Info Disclosure
CVSS 7.5
CVE-2025-24737
MEDIUM
Mat Bao Corporation WP Helper Premium <4.6.1 - Info Disclosure
CVSS 6.5
CVE-2025-24583
MEDIUM
AA Web Servant <3.16.5 - Info Disclosure
CVSS 6.5
CVE-2025-24581
MEDIUM
Themefic Instantio <3.3.7 - Info Disclosure
CVSS 6.5
CVE-2025-24577
MEDIUM
Poll Maker <= 5.5.0 - Missing Authorization
CVSS 6.5
CVE-2025-23958
MEDIUM
FADI MED Editor Wysiwyg Background Color <1.0 - Info Disclosure
CVSS 6.5
CVE-2025-23906
MEDIUM
WordPress Dashboard Tweeter <1.3.2 - RCE
CVSS 6.5
CVE-2025-23773
MEDIUM
mingocommerce Delete All Posts <= 1.1.1 - Missing Authorization
CVSS 6.5
CVE-2025-31338
MEDIUM
Wisdom Master Pro <5.3 - Info Disclosure
CVE-2025-39602
MEDIUM
WC Product Table <3.9.5 - Info Disclosure
CVSS 4.3
CVE-2025-39591
MEDIUM
WP Shuffle WP Subscription Forms <1.2.3 - Info Disclosure
CVSS 5.4
CVE-2025-39571
MEDIUM
WPXPO WowStore <4.2.4 - Info Disclosure
CVSS 4.3
CVE-2025-39560
MEDIUM
Shahjada Live Forms <4.8.4 - Info Disclosure
CVSS 5.4
CVE-2025-39552
MEDIUM
Dylan James Zephyr Project Manager <3.3.200 - Info Disclosure
CVSS 5.4
CVE-2025-39545
MEDIUM
miniOrange WordPress REST API Authentication <= 3.6.3 - Missing Authorization
CVSS 5.4
CVE-2025-39531
MEDIUM
Slazzer Background Changer <3.14 - Info Disclosure
CVSS 5.3
CVE-2025-39522
MEDIUM
Sebastian Lee Dynamic Post <4.10 - Info Disclosure
CVSS 5.4
CVE-2025-39513
MEDIUM
ActiveDEMAND <= 0.2.46 - Missing Authorization
CVSS 5.3
CVE-2025-3687
MEDIUM
misstt123 oasys 1.0 - Cross-Site Request Forgery in Sticky Notes Handler
CVSS 4.3
CVE-2025-30960
HIGH
NotFound FS Poster <6.5.8 - Info Disclosure
CVSS 8.3
Details
Vulnerabilities
8,332
Exploit Likelihood
High