The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,799 vulnerabilities with CWE-862
CVE-2026-61973
MEDIUM
WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-61972
MEDIUM
WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-61954
HIGH
WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-61943
HIGH
WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59547
HIGH
WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-59522
MEDIUM
WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57808
MEDIUM
WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability
CVSS 6.5
CVE-2026-57717
MEDIUM
WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57703
MEDIUM
WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability
CVSS 6.3
CVE-2026-57425
MEDIUM
WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57367
HIGH
WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-27423
MEDIUM
WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-27422
MEDIUM
WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-27418
MEDIUM
WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-27399
MEDIUM
WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-27392
MEDIUM
WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-27391
MEDIUM
WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-27377
MEDIUM
WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability
CVSS 6.7
CVE-2026-27355
MEDIUM
WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-25466
MEDIUM
WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-25427
MEDIUM
WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-25424
MEDIUM
WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-15827
MEDIUM
GutenKit Blocks <= 2.4.12 - Unauthenticated Mailchimp Data Exposure
CVSS 5.3
CVE-2026-15015
CRITICAL
MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint
CVSS 9.8
CVE-2026-59677
MEDIUM
selinux - Process Kill Attack Vector in Killall() in Seunshare
Details
Vulnerabilities
8,799
Exploit Likelihood
High