The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,352 vulnerabilities with CWE-862
CVE-2024-11715
MEDIUM
WP Job Portal - Privilege Escalation
CVSS 4.8
CVE-2024-11712
MEDIUM
WP Job Portal < 2.2.3 - Unauthenticated Exposure of Private Personal Information via getResumeFileDownloadById
CVSS 5.3
CVE-2024-12553
MEDIUM
GeoVision GV-ASManager - Authenticated Information Disclosure via GV-ASWeb Service
CVSS 6.5
CVE-2024-54326
MEDIUM
GEO my WordPress <4.5.0.4 - Info Disclosure
CVSS 6.5
CVE-2024-54323
MEDIUM
WPExpertsio New User Approve <2.6.2 - Info Disclosure
CVSS 5.4
CVE-2024-54311
MEDIUM
Mark New Posts <= 7.5.1 - Missing Authorization
CVSS 5.4
CVE-2024-54310
MEDIUM
Aslam Khan Gouran Gou Manage My Account Menu <1.0.1.8 - Info Disclo...
CVSS 5.3
CVE-2024-54298
MEDIUM
Bill Minozzi Car Dealer <4.46 - Info Disclosure
CVSS 4.3
CVE-2024-54289
MEDIUM
Awesome Support <6.3.0 - Info Disclosure
CVSS 6.5
CVE-2024-54278
MEDIUM
News Ticker for Elementor <2.1.3 - Info Disclosure
CVSS 4.3
CVE-2024-54271
MEDIUM
WPTaskForce WPCargo Track & - Info Disclosure
CVSS 5.4
CVE-2024-54268
MEDIUM
SiteOrigin Widgets Bundle <1.64.0 - RCE
CVSS 4.3
CVE-2024-54267
MEDIUM
CM Answers <3.2.6 - Info Disclosure
CVSS 4.3
CVE-2024-54256
HIGH
Seerox Easy Blocks pro <1.0.21 - RCE
CVSS 7.1
CVE-2024-54252
MEDIUM
Pinpoint Booking System <2.9.9.5.6 - Info Disclosure
CVSS 6.3
CVE-2024-54242
MEDIUM
Appsbd Simple Notification <1.3 - Info Disclosure
CVSS 6.5
CVE-2024-54241
MEDIUM
Appsbd Elite Notification - Missing Authorization
CVSS 6.5
CVE-2024-54239
CRITICAL
dugudlabs Eyewear <4.0.18 - Privilege Escalation
CVSS 9.8
CVE-2024-10783
HIGH
MainWP Child <5.2 - Privilege Escalation
CVSS 8.1
CVE-2024-11911
MEDIUM
WP Crowdfunding <2.1.12 - Privilege Escalation
CVSS 4.3
CVE-2024-12300
LOW
AR for WordPress <7.3 - Unauth File Upload
CVSS 3.7
CVE-2024-55879
CRITICAL
XWiki 2.3-15.10.8 and 16.0.0-16.2.0 - Authenticated Remote Code Execution via ConfigurableClass Instance Addition
CVSS 9.1
CVE-2024-55876
MEDIUM
XWiki 1.2.1-15.10.8 and 16.0.0-16.2.9 - Missing Authorization in Scheduler Operations
CVSS 5.4
CVE-2024-12201
MEDIUM
Hash Form - Drag & Drop Form Builder <= 1.2.1 - Authenticated Missing Authorization for Form Style Creation
CVSS 4.3
CVE-2024-11724
MEDIUM
Cookie Consent for WP - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
8,352
Exploit Likelihood
High