The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,344 vulnerabilities with CWE-862
CVE-2025-26975
MEDIUM
WP Chill Strong Testimonials <3.2.3 - Info Disclosure
CVSS 5.3
CVE-2025-26960
MEDIUM
enuiretechnology Small Package Quotes - Unishippers Edition <2.4.9 ...
CVSS 6.5
CVE-2025-26948
MEDIUM
NotFound Pie Register Premium <3.8.3.2 - Info Disclosure
CVSS 4.3
CVE-2025-26928
MEDIUM
xfinitysoft Order Limit for WooCommerce <3.0.2 - Info Disclosure
CVSS 4.3
CVE-2025-26871
MEDIUM
WPDeveloper Essential Blocks for Gutenberg <= 4.8.3 - Missing Authorization
CVSS 4.3
CVE-2025-1644
MEDIUM
Benner ModernaNet < 1.2.1 - Cross-Site Request Forgery via idItAg Argument
CVSS 4.3
CVE-2025-1643
MEDIUM
Benner ModernaNet < 1.1.1 - Cross-Site Request Forgery in /DadosPessoais/SG_AlterarSenha
CVSS 4.3
CVE-2025-27356
MEDIUM
Hardik Sticky Header On Scroll <1.0 - RCE
CVSS 5.4
CVE-2025-27296
HIGH
Revenueflex Auto Ad Inserter - Info Disclosure
CVSS 7.2
CVE-2025-27294
MEDIUM
platcom WP-Asambleas <2.85.0 - Info Disclosure
CVSS 4.8
CVE-2025-26883
MEDIUM
bPlugins Animated Text Block <1.0.8 - Info Disclosure
CVSS 6.5
CVE-2025-26764
MEDIUM
Distance Based Shipping Calculator <2.0.22 - Info Disclosure
CVSS 6.5
CVE-2025-26750
MEDIUM
appsbd Vitepos <3.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-1557
MEDIUM
OFCMS 1.1.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-1361
HIGH
IP2Location Country Blocker <= 2.38.8 - Unauthenticated Regular Information Exposure via admin_init()
CVSS 7.5
CVE-2025-1402
MEDIUM
Event Tickets and Registration <= 5.19.1.1 - Arbitrary Attendee Ticket Deletion
CVSS 5.3
CVE-2025-1483
MEDIUM
GlobalTranz LTL Freight Quotes <= 2.3.12 - Unauthenticated Data Modification
CVSS 5.3
CVE-2025-0968
MEDIUM
ElementsKit Elementor Addons < 3.4.0 - Unauthenticated Sensitive Information Exposure via get_megamenu_content()
CVSS 5.3
CVE-2025-27013
MEDIUM
EPC MediCenter - Health Medical Clinic WordPress Theme <n/a - Info ...
CVSS 5.3
CVE-2025-22657
HIGH
Atarim <= 4.0.9 - Missing Authorization for Content Deletion
CVSS 7.5
CVE-2025-26773
MEDIUM
Analytify < 5.5.1 - Missing Authorization
CVSS 4.3
CVE-2025-26765
MEDIUM
Distance Based Shipping Calculator <2.0.22 - Info Disclosure
CVSS 5.4
CVE-2025-22291
MEDIUM
enituretechnology LTL Freight Quotes - Worldwide Express Edition <5...
CVSS 5.3
CVE-2025-22289
MEDIUM
LTL Freight Quotes - Unishippers Edition <= 2.5.8 - Missing Authorization
CVSS 6.5
CVE-2025-1358
MEDIUM
Pix Software Vivaz 6.0.10 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities
8,344
Exploit Likelihood
High