The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,808 vulnerabilities with CWE-862
CVE-2026-57430
MEDIUM
WordPress SEOPress PRO plugin <= 9.1.1 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57324
MEDIUM
WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57323
MEDIUM
WordPress Flash & HTML5 Video plugin <= 2.11.0 - Broken Access Control vulnerability
CVSS 5.8
CVE-2026-56773
HIGH
Teable - Missing Authorization in v2 REST API
CVSS 8.8
CVE-2026-56063
HIGH
WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability
CVSS 8.3
CVE-2026-56061
HIGH
WordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-56038
HIGH
WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-56025
HIGH
WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54847
HIGH
WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54846
HIGH
WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54840
HIGH
WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-54837
HIGH
WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54835
HIGH
WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54832
HIGH
WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-52701
MEDIUM
WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-24547
MEDIUM
WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57925
MEDIUM
Jetbrains YouTrack < 2026.2.16593 - Missing Authorization
CVSS 4.3
CVE-2026-57923
MEDIUM
Jetbrains YouTrack < 2026.2.16593 - Missing Authorization
CVSS 5.3
CVE-2026-57922
LOW
Jetbrains YouTrack < 2026.2.16593 - Missing Authorization
CVSS 3.1
CVE-2026-57921
MEDIUM
Jetbrains YouTrack < 2026.2.16593 - Missing Authorization
CVSS 4.3
CVE-2026-1869
MEDIUM
User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass
CVSS 6.5
CVE-2026-57521
MEDIUM
Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
CVSS 4.3
CVE-2026-57520
HIGH
Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
CVSS 7.1
CVE-2026-2299
MEDIUM
Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
CVSS 4.2
CVE-2026-56768
HIGH
Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method
CVSS 8.8
Details
Vulnerabilities
8,808
Exploit Likelihood
High