The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,346 vulnerabilities with CWE-862
CVE-2024-12365
HIGH
W3 Total Cache <= 2.8.1 - Authenticated Missing Authorization in is_w3tc_admin_page
CVSS 8.5
CVE-2024-12006
MEDIUM
W3 Total Cache <= 2.8.1 - Unauthenticated Plugin Extension Activation/Deactivation
CVSS 5.3
CVE-2024-12204
MEDIUM
Coupon X: Discount Pop Up - Privilege Escalation
CVSS 5.4
CVE-2024-12606
MEDIUM
AI Scribe WordPress Plugin < 2.5 - Authenticated Missing Authorization
CVSS 4.3
CVE-2024-13312
MEDIUM
Drupal Open Social <12.3.10-12.4.9 - Forceful Browsing
CVSS 5.3
CVE-2024-13303
MEDIUM
Drupal Download All Files <2.0.2 - Forceful Browsing
CVSS 5.3
CVE-2024-13243
MEDIUM
Drupal Entity Delete Log <1.1.1 - Forceful Browsing
CVSS 6.5
CVE-2024-6155
MEDIUM
Greenshift < 9.0.1 - Authenticated SSRF & Stored XSS via SVG Upload
CVSS 6.4
CVE-2024-5769
MEDIUM
MIMO Woocommerce Order Tracking <1.0.2 - Info Disclosure
CVSS 4.3
CVE-2024-12848
HIGH
SKT Page Builder <= 4.6 - Authenticated Arbitrary File Upload via addLibraryByArchive Function
CVSS 8.8
CVE-2024-12618
MEDIUM
Newsletter2Go <4.0.14 - Info Disclosure
CVSS 4.3
CVE-2024-12616
MEDIUM
Bitly's WordPress Plugin <2.7.3 - Info Disclosure
CVSS 4.3
CVE-2024-12542
HIGH
linkID WordPress <0.1.2 - Info Disclosure
CVSS 8.6
CVE-2024-12249
MEDIUM
GS Insever Portfolio <1.4.5 - Info Disclosure
CVSS 4.3
CVE-2024-11929
MEDIUM
Responsive FlipBook Plugin <2.5.0 - XSS
CVSS 6.4
CVE-2024-43662
MEDIUM
Iocharger AC <24120701 - File Upload
CVE-2024-13203
MEDIUM
kurniaramadhan E-Commerce-PHP 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-12431
MEDIUM
GitLab 15.5-17.5.4, 17.6-17.6.2, 17.7 - Unauthenticated Issue Status Manipulation in Public Projects
CVSS 4.3
CVE-2024-11423
HIGH
The Ultimate Gift Cards for WooCommerce <3.0.6 - Info Disclosure
CVSS 7.5
CVE-2024-12712
MEDIUM
Shopping Cart & eCommerce Store <5.7.8 - Info Disclosure
CVSS 5.3
CVE-2024-12855
MEDIUM
AdForest < 5.1.7 - Authenticated Unauthorized Data Modification via AJAX Actions
CVSS 4.3
CVE-2024-11271
HIGH
WebinarPress < 1.33.24 - Authenticated Data Modification via Missing Capability Check
CVSS 8.8
CVE-2024-11270
HIGH
WebinarPress < 1.33.24 - Authenticated Arbitrary File Creation via sync-import-imgs Function
CVSS 8.8
CVE-2024-12713
MEDIUM
SureForms < 1.2.3 - Unauthenticated Information Exposure via handle_export_form()
CVSS 5.3
CVE-2024-11916
HIGH
WP Extended <3.0.11 - Info Disclosure
CVSS 7.4
Details
Vulnerabilities
8,346
Exploit Likelihood
High