The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,230 vulnerabilities with CWE-862
CVE-2026-1499
HIGH
WP Duplicate - WordPress Migration Plugin <= 1.1.8 - Authenticated Arbitrary File Upload via Missing Authorization
CVSS 8.8
CVE-2026-1927
MEDIUM
Greenshift <= 12.6 - Authenticated Missing Authorization & Stored XSS via greenshift_app_pass_validation()
CVSS 5.4
CVE-2026-1897
MEDIUM
WeKan < 8.21 - Missing Authorization in Position-History Tracking
CVSS 4.3
CVE-2026-25538
HIGH
Devtron < 2.0.0 - Authenticated JWT Token Forgery via Attributes API
CVSS 8.8
CVE-2026-25517
LOW
Wagtail < 6.3.6 - Missing Authorization in Preview Endpoints
CVSS 2.7
CVE-2026-0679
MEDIUM
Fortis for WooCommerce <1.2.0 - Auth Bypass
CVSS 5.3
CVE-2026-0572
MEDIUM
WebPurify Profanity Filter <4.0.2 - Info Disclosure
CVSS 6.5
CVE-2026-1835
MEDIUM
lcg0124 BootDo <e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb - CSRF
CVSS 4.3
CVE-2026-25036
MEDIUM
WP Chill Passster <4.2.25 - Info Disclosure
CVSS 6.5
CVE-2026-25028
MEDIUM
Element Invader ElementInvader Addons for Elementor <2.5 - Info Dis...
CVSS 5.4
CVE-2026-25021
MEDIUM
Mizan Themes Mizan Demo Importer <0.1.4 - RCE
CVSS 5.4
CVE-2026-25020
MEDIUM
WP Sync for Notion <1.7.0 - Info Disclosure
CVSS 4.3
CVE-2026-25019
MEDIUM
Atarim <= 4.3.1 - Missing Authorization
CVSS 5.3
CVE-2026-25016
MEDIUM
Nelio Popups <1.3.5 - Info Disclosure
CVSS 4.3
CVE-2026-25012
MEDIUM
WP Bannerize Pro <= 1.11.0 - Missing Authorization
CVSS 5.3
CVE-2026-25011
MEDIUM
Northern Beaches Websites WP Custom Admin Interface <8 - Info Discl...
CVSS 4.3
CVE-2026-25010
MEDIUM
ILLID Share This Image <= 2.09 - Missing Authorization
CVSS 5.3
CVE-2026-24997
MEDIUM
Wired Impact Volunteer Management <2.9 - RCE
CVSS 5.3
CVE-2026-24996
MEDIUM
WPElemento Importer <= 0.6.4 - Missing Authorization
CVSS 4.3
CVE-2026-24995
MEDIUM
Latest Post Shortcode <15 - Auth Bypass
CVSS 4.3
CVE-2026-24994
MEDIUM
Sunshine Photo Cart <3.5.7.2 - Info Disclosure
CVSS 5.3
CVE-2026-24990
MEDIUM
Fahad Mahmood WP Docs <= 2.2.8 - Missing Authorization
CVSS 5.4
CVE-2026-24985
MEDIUM
WP Forms Signature Contract Add-On <1.8.3 - Info Disclosure
CVSS 4.3
CVE-2026-24984
MEDIUM
Brecht Visual Link Preview <= 2.2.9 - Missing Authorization
CVSS 6.5
CVE-2026-24982
MEDIUM
Brainstorm Force Spectra <=2.19.17 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,230
Exploit Likelihood
High