The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,808 vulnerabilities with CWE-862
CVE-2026-57685
MEDIUM
WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57669
MEDIUM
WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57355
MEDIUM
WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57353
MEDIUM
WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-39448
HIGH
WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-27433
MEDIUM
WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-13459
MEDIUM
JetMonsters JetFormBuilder <= 3.6.3 - Unauthenticated Post Meta Disclosure
CVSS 5.3
CVE-2026-12472
MEDIUM
Freeform Page Builder, Website Builder & Customizer < 6.0.11 - Authorization Bypass
CVSS 5.3
CVE-2026-12134
MEDIUM
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
CVSS 4.3
CVE-2026-12122
MEDIUM
Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
CVSS 5.3
CVE-2026-11600
MEDIUM
Envo's Templates & Widgets For Elementor And WooCommerce < 1.4.26 - Information Exposure
CVSS 4.3
CVE-2026-11592
MEDIUM
Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
CVSS 4.3
CVE-2026-50284
HIGH
Craft CMS < 4.17.15 and < 5.9.22 - Peer Asset Deletion Authorization Bypass
CVE-2026-50283
MEDIUM
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-55628
MEDIUM
ImageMagick: Policy Bypass in concatenate operation due to missing checks
CVSS 5.5
CVE-2026-57721
MEDIUM
WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57720
MEDIUM
WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-27409
MEDIUM
WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-23537
CRITICAL
Feast: unauthenticated arbitrary file write
CVSS 9.1
CVE-2026-27435
MEDIUM
WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-12435
MEDIUM
Stylemix Motors <= 1.4.111 - Subscriber+ Car Listing Sold-State Tampering
CVSS 4.3
CVE-2026-1239
HIGH
Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
CVSS 7.5
CVE-2026-13468
HIGH
Visualizer <= 4.0.3 - Unauthenticated Chart Data Export via REST Endpoint
CVSS 7.5
CVE-2026-12902
MEDIUM
Kadence Blocks — Page Builder Toolkit For Gutenberg Editor < 3.7.7 - Authorization Bypass
CVSS 4.3
CVE-2026-12133
MEDIUM
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
CVSS 4.3
Details
Vulnerabilities
8,808
Exploit Likelihood
High