CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,344 vulnerabilities with CWE-862
CVE-2025-26975 MEDIUM
WP Chill Strong Testimonials <3.2.3 - Info Disclosure
CVSS 5.3
CVE-2025-26960 MEDIUM
enuiretechnology Small Package Quotes - Unishippers Edition <2.4.9 ...
CVSS 6.5
CVE-2025-26948 MEDIUM
NotFound Pie Register Premium <3.8.3.2 - Info Disclosure
CVSS 4.3
CVE-2025-26928 MEDIUM
xfinitysoft Order Limit for WooCommerce <3.0.2 - Info Disclosure
CVSS 4.3
CVE-2025-26871 MEDIUM
WPDeveloper Essential Blocks for Gutenberg <= 4.8.3 - Missing Authorization
CVSS 4.3
CVE-2025-1644 MEDIUM
Benner ModernaNet < 1.2.1 - Cross-Site Request Forgery via idItAg Argument
CVSS 4.3
CVE-2025-1643 MEDIUM
Benner ModernaNet < 1.1.1 - Cross-Site Request Forgery in /DadosPessoais/SG_AlterarSenha
CVSS 4.3
CVE-2025-27356 MEDIUM
Hardik Sticky Header On Scroll <1.0 - RCE
CVSS 5.4
CVE-2025-27296 HIGH
Revenueflex Auto Ad Inserter - Info Disclosure
CVSS 7.2
CVE-2025-27294 MEDIUM
platcom WP-Asambleas <2.85.0 - Info Disclosure
CVSS 4.8
CVE-2025-26883 MEDIUM
bPlugins Animated Text Block <1.0.8 - Info Disclosure
CVSS 6.5
CVE-2025-26764 MEDIUM
Distance Based Shipping Calculator <2.0.22 - Info Disclosure
CVSS 6.5
CVE-2025-26750 MEDIUM
appsbd Vitepos <3.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-1557 MEDIUM
OFCMS 1.1.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-1361 HIGH
IP2Location Country Blocker <= 2.38.8 - Unauthenticated Regular Information Exposure via admin_init()
CVSS 7.5
CVE-2025-1402 MEDIUM
Event Tickets and Registration <= 5.19.1.1 - Arbitrary Attendee Ticket Deletion
CVSS 5.3
CVE-2025-1483 MEDIUM
GlobalTranz LTL Freight Quotes <= 2.3.12 - Unauthenticated Data Modification
CVSS 5.3
CVE-2025-0968 MEDIUM
ElementsKit Elementor Addons < 3.4.0 - Unauthenticated Sensitive Information Exposure via get_megamenu_content()
CVSS 5.3
CVE-2025-27013 MEDIUM
EPC MediCenter - Health Medical Clinic WordPress Theme <n/a - Info ...
CVSS 5.3
CVE-2025-22657 HIGH
Atarim <= 4.0.9 - Missing Authorization for Content Deletion
CVSS 7.5
CVE-2025-26773 MEDIUM
Analytify < 5.5.1 - Missing Authorization
CVSS 4.3
CVE-2025-26765 MEDIUM
Distance Based Shipping Calculator <2.0.22 - Info Disclosure
CVSS 5.4
CVE-2025-22291 MEDIUM
enituretechnology LTL Freight Quotes - Worldwide Express Edition <5...
CVSS 5.3
CVE-2025-22289 MEDIUM
LTL Freight Quotes - Unishippers Edition <= 2.5.8 - Missing Authorization
CVSS 6.5
CVE-2025-1358 MEDIUM
Pix Software Vivaz 6.0.10 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 8,344
Exploit Likelihood High