CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,213 vulnerabilities with CWE-862
CVE-2026-32583 MEDIUM
WordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-2463 MEDIUM
Unauthorized access to invite ID during team creation
CVSS 4.3
CVE-2026-2458 MEDIUM
Unauthorized channel enumeration in private teams after member removal
CVSS 4.3
CVE-2026-2233 MEDIUM
User Frontend WordPress Plugin <=4.2.8 - Auth Bypass
CVSS 5.3
CVE-2026-25083 HIGH
GROWI v7.4.5 and earlier - Auth Bypass
CVSS 8.3
CVE-2026-1948 MEDIUM
NEX-Forms - Ultimate Forms Plugin for WordPress <=9.1.9 - Auth Bypass
CVSS 4.3
CVE-2026-1870 MEDIUM
Thim Kit for Elementor <1.3.7 - Info Disclosure
CVSS 5.3
CVE-2026-4063 MEDIUM
Social Icons Widget & Block by WPZOOM - Auth Bypass
CVSS 4.3
CVE-2026-3045 HIGH
Appointment Booking Calendar 1.6.9.29 - Info Disclosure
CVSS 7.5
CVE-2026-32543 MEDIUM
Responsive Blocks <=2.2.0 - Auth Bypass
CVSS 5.3
CVE-2026-32487 MEDIUM
Lawyer Landing Page <=1.2.7 - Auth Bypass
CVSS 5.3
CVE-2026-32486 MEDIUM
Travel Booking <=1.3.9 - Auth Bypass
CVSS 5.3
CVE-2026-32461 MEDIUM
Really Simple SSL <=9.5.7 - Auth Bypass
CVSS 4.3
CVE-2026-32457 MEDIUM
Advanced Product Fields for WooCommerce <=1.6.18 - Auth Bypass
CVSS 5.3
CVE-2026-32453 MEDIUM
ThemeFusion Avada Core <5.15.0 - Auth Bypass
CVSS 5.3
CVE-2026-32452 MEDIUM
ThemeFusion Fusion Builder <3.15.0 - Auth Bypass
CVSS 5.3
CVE-2026-32451 MEDIUM
Fusion Builder <3.15.0 - Auth Bypass
CVSS 6.5
CVE-2026-32447 MEDIUM
Atarim <= 4.3.2 - Missing Authorization
CVSS 4.3
CVE-2026-32446 MEDIUM
Contact Form by WPForms <=1.9.9.3 - Auth Bypass
CVSS 4.3
CVE-2026-32445 LOW
Elementor Website Builder <=3.35.5 - Auth Bypass
CVSS 2.7
CVE-2026-32442 MEDIUM
E2Pdf e2pdf <= 1.28.15 - Missing Authorization
CVSS 5.0
CVE-2026-32440 MEDIUM
Ex-Themes WP Food < 2.7.1 - Missing Authorization
CVSS 5.3
CVE-2026-32439 MEDIUM
BigHearts <= 3.1.14 - Missing Authorization
CVSS 5.3
CVE-2026-32438 MEDIUM
vw-school-education <=1.4.6 - Auth Bypass
CVSS 5.3
CVE-2026-32437 MEDIUM
VW Portfolio <= 1.3.3 - Missing Authorization
CVSS 5.3
Details
Vulnerabilities 8,213
Exploit Likelihood High