CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,794 vulnerabilities with CWE-862
CVE-2026-66750 MEDIUM
Let's Chat 0.3.0-0.4.8 - Authenticated File Disclosure via GET /files
CVSS 4.3
CVE-2026-16774 MEDIUM
WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action
CVSS 5.3
CVE-2026-15411 MEDIUM
Upsell, Bogo, Quick View, Direct Checkout & Side Cart For WooCommerce < 2.1.0 - Authorization Bypass
CVSS 5.3
CVE-2026-15025 HIGH
Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
CVSS 7.5
CVE-2026-13110 MEDIUM
StoreGrowth Sales Booster <= 2.1.0 - Unauthenticated Settings Modification
CVSS 5.3
CVE-2026-14168 HIGH
ads-tec Industrial IT: Vertical privilege escalation via configuration table write
CVSS 8.8
CVE-2026-16587 MEDIUM
Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function
CVSS 4.3
CVE-2026-14924 HIGH
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
CVSS 7.5
CVE-2026-14821 LOW
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVSS 2.7
CVE-2026-12124 MEDIUM
PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter
CVSS 5.3
CVE-2026-66473 HIGH
WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-65445 MEDIUM
WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-64746 CRITICAL
Apple Ios And iPadOS - Denial of Service
CVSS 9.8
CVE-2026-43665 MEDIUM
macOS < 14.8.8 and < 15.7.8 - Unprotected Screen Sharing VNC Password Exposure via Missing Entitlement Checks
CVSS 5.5
CVE-2026-65922 HIGH
Potential unauthorized modification of Artifactory internal metadata
CVSS 7.1
CVE-2026-66477 MEDIUM
WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-66442 MEDIUM
WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-65568 MEDIUM
WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability
CVSS 5.0
CVE-2026-65567 MEDIUM
WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-65435 MEDIUM
WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-65433 MEDIUM
WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59560 MEDIUM
WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59557 MEDIUM
WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59536 HIGH
WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59535 HIGH
WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability
CVSS 7.3
Details
Vulnerabilities 8,794
Exploit Likelihood High