CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,222 vulnerabilities with CWE-862
CVE-2026-25321 MEDIUM
SupportCandy <=3.4.4 - Privilege Escalation
CVSS 5.3
CVE-2026-25320 MEDIUM
Elementor Contact Form DB <=2.1.3 - Auth Bypass
CVSS 5.3
CVE-2026-25318 MEDIUM
WiserReview Product Reviews for WooCommerce <= 2.9 - Missing Authorization
CVSS 4.3
CVE-2026-25315 MEDIUM
hCaptcha for WP <=4.22.0 - Auth Bypass
CVSS 5.3
CVE-2026-25314 MEDIUM
WP Messiah TOP Table Of Contents <=1.3.31 - Auth Bypass
CVSS 4.3
CVE-2026-25313 MEDIUM
FluentForm <=6.1.14 - Privilege Escalation
CVSS 4.3
CVE-2026-25311 MEDIUM
Autoshare for Twitter <=2.3.1 - Auth Bypass
CVSS 5.4
CVE-2026-25308 MEDIUM
Simple Membership <=4.6.9 - Auth Bypass
CVSS 4.3
CVE-2026-25003 MEDIUM
Client Portal <=1.2.1 - Auth Bypass
CVSS 4.3
CVE-2026-25000 MEDIUM
Kraft Plugins Wheel of Life <=1.2.0 - Auth Bypass
CVSS 5.3
CVE-2026-24999 MEDIUM
Alma alma-gateway-for-woocommerce <=5.16.1 - Auth Bypass
CVSS 5.3
CVE-2026-24375 MEDIUM
WP Swings Ultimate Gift Cards <=3.2.4 - Auth Bypass
CVSS 5.3
CVE-2026-23804 MEDIUM
BBR Plugins Better Business Reviews <=0.1.1 - Auth Bypass
CVSS 5.4
CVE-2026-23548 MEDIUM
DirectoryPress <=3.6.25 - Auth Bypass
CVSS 5.3
CVE-2026-23547 HIGH
CMSMasters Content Composer <=2.5.8 - Auth Bypass
CVSS 7.1
CVE-2026-23545 MEDIUM
Aruba HiSpeed Cache <=3.0.4 - Auth Bypass
CVSS 6.5
CVE-2026-23543 MEDIUM
WPDeveloper Essential Addons <=6.5.5 - Auth Bypass
CVSS 5.3
CVE-2026-23541 HIGH
WPFunnels Mail Mint <=1.19.4 - Auth Bypass
CVSS 7.5
CVE-2026-2504 MEDIUM
Dealia WordPress Plugin <=1.0.6 - Privilege Escalation
CVSS 4.3
CVE-2026-2284 MEDIUM
News Element Elementor Blog Magazine <=1.0.8 - Missing Authorization
CVSS 5.4
CVE-2026-25242 CRITICAL
Gogs <=0.13.4 - Unauthenticated File Upload
CVSS 9.8
CVE-2026-0974 HIGH
Orderable WordPress Plugin <=1.20.0 - Authenticated RCE
CVSS 8.8
CVE-2026-27181 HIGH
MajorDoMo - Unauthenticated Arbitrary Module Uninstallation via Market Endpoint
CVSS 7.5
CVE-2026-1355 MEDIUM
GitHub Enterprise Server - Auth Bypass
CVSS 6.5
CVE-2026-2658 MEDIUM
newbee-mall < a069069b07027613bf0e7f571736be86f431faee - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 8,222
Exploit Likelihood High