The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,794 vulnerabilities with CWE-862
CVE-2026-66750
MEDIUM
Let's Chat 0.3.0-0.4.8 - Authenticated File Disclosure via GET /files
CVSS 4.3
CVE-2026-16774
MEDIUM
WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action
CVSS 5.3
CVE-2026-15411
MEDIUM
Upsell, Bogo, Quick View, Direct Checkout & Side Cart For WooCommerce < 2.1.0 - Authorization Bypass
CVSS 5.3
CVE-2026-15025
HIGH
Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
CVSS 7.5
CVE-2026-13110
MEDIUM
StoreGrowth Sales Booster <= 2.1.0 - Unauthenticated Settings Modification
CVSS 5.3
CVE-2026-14168
HIGH
ads-tec Industrial IT: Vertical privilege escalation via configuration table write
CVSS 8.8
CVE-2026-16587
MEDIUM
Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function
CVSS 4.3
CVE-2026-14924
HIGH
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
CVSS 7.5
CVE-2026-14821
LOW
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVSS 2.7
CVE-2026-12124
MEDIUM
PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter
CVSS 5.3
CVE-2026-66473
HIGH
WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-65445
MEDIUM
WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-64746
CRITICAL
Apple Ios And iPadOS - Denial of Service
CVSS 9.8
CVE-2026-43665
MEDIUM
macOS < 14.8.8 and < 15.7.8 - Unprotected Screen Sharing VNC Password Exposure via Missing Entitlement Checks
CVSS 5.5
CVE-2026-65922
HIGH
Potential unauthorized modification of Artifactory internal metadata
CVSS 7.1
CVE-2026-66477
MEDIUM
WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-66442
MEDIUM
WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-65568
MEDIUM
WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability
CVSS 5.0
CVE-2026-65567
MEDIUM
WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-65435
MEDIUM
WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-65433
MEDIUM
WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59560
MEDIUM
WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59557
MEDIUM
WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59536
HIGH
WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59535
HIGH
WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability
CVSS 7.3
Details
Vulnerabilities
8,794
Exploit Likelihood
High