The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,799 vulnerabilities with CWE-862
CVE-2026-65433
MEDIUM
WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59560
MEDIUM
WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59557
MEDIUM
WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-59536
HIGH
WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59535
HIGH
WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-59534
HIGH
WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59530
HIGH
WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59529
HIGH
WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-59690
HIGH
Progress LoadMaster Family - Authenticated REST API Missing Authorization
CVSS 8.0
CVE-2026-13390
MEDIUM
The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation
CVSS 5.3
CVE-2026-66012
CRITICAL
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
CVSS 10.0
CVE-2026-66027
HIGH
Suna < 0.9.102 Broken Access Control via Message Queue API
CVSS 8.3
CVE-2026-49326
MEDIUM
Apache HBase: Missing scanner instance owner check in thrift delegation service
CVSS 6.5
CVE-2026-16799
MEDIUM
Devolutions PowerShell Universal < 2026.2.3 - Missing Authorization
CVSS 5.0
CVE-2026-10033
HIGH
EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action
CVSS 7.3
CVE-2026-12654
MEDIUM
Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret
CVSS 5.3
CVE-2026-12690
LOW
ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization
CVSS 3.8
CVE-2026-12689
MEDIUM
ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
CVSS 5.4
CVE-2026-11354
MEDIUM
Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter
CVSS 5.3
CVE-2026-58275
CRITICAL
Azure DNS Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-47724
CRITICAL
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
CVSS 9.9
CVE-2026-47755
MEDIUM
ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal
CVSS 6.5
CVE-2026-65916
HIGH
CyberPanel Missing Authorization in cancelBackupCreation Handler
CVSS 8.1
CVE-2026-65895
HIGH
Grav API Plugin before 1.0.10 Broken Access Control
CVSS 8.5
CVE-2026-65537
MEDIUM
WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability
CVSS 4.3
Details
Vulnerabilities
8,799
Exploit Likelihood
High