CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,333 vulnerabilities with CWE-862
CVE-2025-1233 MEDIUM
Lafka Plugin <7.1.0 - Privilege Escalation
CVSS 4.3
CVE-2025-2933 HIGH
WordPress Email Notifications <1.1.6 - Privilege Escalation
CVSS 8.8
CVE-2025-3257 MEDIUM
xujiangfei admintwo 1.0 - Cross-Site Request Forgery via /user/updateSet
CVSS 4.3
CVE-2025-32277 MEDIUM
Ateeq Rafeeq RepairBuddy <3.8211 - Privilege Escalation
CVSS 4.3
CVE-2025-32258 MEDIUM
Simple Website Logo <= 1.1 - Missing Authorization
CVSS 5.3
CVE-2025-32256 MEDIUM
SurveyJS <1.12.20 - Info Disclosure
CVSS 5.3
CVE-2025-32254 MEDIUM
Iqonic Design WPBookit <= 1.0.7 - Missing Authorization
CVSS 5.3
CVE-2025-32253 MEDIUM
ComMotion Course Booking System <6.0.5 - Info Disclosure
CVSS 5.3
CVE-2025-32252 MEDIUM
WP Genealogy - Your Family History Website <= 0.1.9 - Missing Authorization
CVSS 5.3
CVE-2025-32246 MEDIUM
Tim Nguyen 1-Click Backup &amp;amp; Restore Database - Info Disclosure
CVSS 5.4
CVE-2025-32239 MEDIUM
Joao Romao Social Share Buttons & Analytics Plugin - Info Disclosure
CVSS 4.3
CVE-2025-32237 MEDIUM
Stylemix MasterStudy LMS <3.5.23 - Privilege Escalation
CVSS 4.3
CVE-2025-32235 MEDIUM
Sonaar MP3 Audio Player <5.9.4 - Info Disclosure
CVSS 4.3
CVE-2025-32234 MEDIUM
AdMail - Multilingual Back in-Stock Notifier for WooCommerce <1.7.0...
CVSS 4.3
CVE-2025-32233 MEDIUM
WP Chill Revive.so - Info Disclosure
CVSS 4.3
CVE-2025-32232 MEDIUM
ERA404 StaffList <3.2.6 - Info Disclosure
CVSS 4.3
CVE-2025-32231 MEDIUM
Bookingor <= 2.0.1 - Missing Authorization
CVSS 4.3
CVE-2025-32229 MEDIUM
Bowo Variable Inspector <2.6.3 - RCE
CVSS 4.3
CVE-2025-32226 MEDIUM
Display product variations dropdown on shop page <= 1.1.3 - Missing Authorization
CVSS 4.3
CVE-2025-32225 MEDIUM
WP Event Manager <3.1.47 - Info Disclosure
CVSS 5.3
CVE-2025-32224 MEDIUM
Privyr CRM <1.0.1 - Info Disclosure
CVSS 5.4
CVE-2025-32220 MEDIUM
Salon booking system <= 10.30.23 - Missing Authorization
CVSS 5.4
CVE-2025-32219 MEDIUM
Syntactics, Inc. eaSYNC <1.3.19 - Info Disclosure
CVSS 5.4
CVE-2025-32218 MEDIUM
TableOn - WordPress Posts Table Filterable <1.0.5 - RCE
CVSS 5.4
CVE-2025-32217 MEDIUM
WP Messiah Ai Image Alt Text Generator <1.0.8 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 8,333
Exploit Likelihood High