The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,213 vulnerabilities with CWE-862
CVE-2026-32583
MEDIUM
WordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-2463
MEDIUM
Unauthorized access to invite ID during team creation
CVSS 4.3
CVE-2026-2458
MEDIUM
Unauthorized channel enumeration in private teams after member removal
CVSS 4.3
CVE-2026-2233
MEDIUM
User Frontend WordPress Plugin <=4.2.8 - Auth Bypass
CVSS 5.3
CVE-2026-25083
HIGH
GROWI v7.4.5 and earlier - Auth Bypass
CVSS 8.3
CVE-2026-1948
MEDIUM
NEX-Forms - Ultimate Forms Plugin for WordPress <=9.1.9 - Auth Bypass
CVSS 4.3
CVE-2026-1870
MEDIUM
Thim Kit for Elementor <1.3.7 - Info Disclosure
CVSS 5.3
CVE-2026-4063
MEDIUM
Social Icons Widget & Block by WPZOOM - Auth Bypass
CVSS 4.3
CVE-2026-3045
HIGH
Appointment Booking Calendar 1.6.9.29 - Info Disclosure
CVSS 7.5
CVE-2026-32543
MEDIUM
Responsive Blocks <=2.2.0 - Auth Bypass
CVSS 5.3
CVE-2026-32487
MEDIUM
Lawyer Landing Page <=1.2.7 - Auth Bypass
CVSS 5.3
CVE-2026-32486
MEDIUM
Travel Booking <=1.3.9 - Auth Bypass
CVSS 5.3
CVE-2026-32461
MEDIUM
Really Simple SSL <=9.5.7 - Auth Bypass
CVSS 4.3
CVE-2026-32457
MEDIUM
Advanced Product Fields for WooCommerce <=1.6.18 - Auth Bypass
CVSS 5.3
CVE-2026-32453
MEDIUM
ThemeFusion Avada Core <5.15.0 - Auth Bypass
CVSS 5.3
CVE-2026-32452
MEDIUM
ThemeFusion Fusion Builder <3.15.0 - Auth Bypass
CVSS 5.3
CVE-2026-32451
MEDIUM
Fusion Builder <3.15.0 - Auth Bypass
CVSS 6.5
CVE-2026-32447
MEDIUM
Atarim <= 4.3.2 - Missing Authorization
CVSS 4.3
CVE-2026-32446
MEDIUM
Contact Form by WPForms <=1.9.9.3 - Auth Bypass
CVSS 4.3
CVE-2026-32445
LOW
Elementor Website Builder <=3.35.5 - Auth Bypass
CVSS 2.7
CVE-2026-32442
MEDIUM
E2Pdf e2pdf <= 1.28.15 - Missing Authorization
CVSS 5.0
CVE-2026-32440
MEDIUM
Ex-Themes WP Food < 2.7.1 - Missing Authorization
CVSS 5.3
CVE-2026-32439
MEDIUM
BigHearts <= 3.1.14 - Missing Authorization
CVSS 5.3
CVE-2026-32438
MEDIUM
vw-school-education <=1.4.6 - Auth Bypass
CVSS 5.3
CVE-2026-32437
MEDIUM
VW Portfolio <= 1.3.3 - Missing Authorization
CVSS 5.3
Details
Vulnerabilities
8,213
Exploit Likelihood
High