The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,232 vulnerabilities with CWE-862
CVE-2026-1103
MEDIUM
AIKTP WordPress <5.0.04 - Info Disclosure
CVSS 5.4
CVE-2026-24421
MEDIUM
phpmyfaq < 4.0.17 - Authenticated Missing Authorization in Setup Backup Endpoint
CVSS 6.5
CVE-2026-24139
MEDIUM
MyTube < 1.7.78 - Unauthenticated Database Export via Missing Authorization
CVSS 6.5
CVE-2026-24636
MEDIUM
Sugar Calendar Lite <3.10.1 - Info Disclosure
CVSS 4.3
CVE-2026-24633
MEDIUM
Passionate Brains Add Expires Headers & Optimized Minify <3.1.0 - I...
CVSS 5.3
CVE-2026-24627
MEDIUM
Trusona for WordPress <= 2.0.0 - Info Disclosure
CVSS 4.3
CVE-2026-24625
MEDIUM
Imaginate Solutions File Uploads Addon - RCE
CVSS 5.3
CVE-2026-24622
MEDIUM
Sergiy Dzysyak Suggestion Toolkit <5.0 - Info Disclosure
CVSS 5.4
CVE-2026-24619
MEDIUM
PopCash Net Code Integration Tool <1.9 - RCE
CVSS 5.3
CVE-2026-24616
MEDIUM
Damian WP Popups <2.2.0.3 - Info Disclosure
CVSS 6.5
CVE-2026-24615
MEDIUM
themebeez Cream Magazine <2.1.10 - Info Disclosure
CVSS 5.3
CVE-2026-24613
MEDIUM
Ecwid Shopping Cart <7.0.5 - Info Disclosure
CVSS 5.3
CVE-2026-24612
MEDIUM
Orchid Store <= 1.5.15 - Missing Authorization
CVSS 5.3
CVE-2026-24607
MEDIUM
wptravelengine Travel Monster <1.3.3 - RCE
CVSS 5.3
CVE-2026-24606
MEDIUM
Bayarcash WooCommerce <4.3.11 - RCE
CVSS 5.3
CVE-2026-24605
MEDIUM
pencilwp X Addons for Elementor <1.0.23 - RCE
CVSS 4.3
CVE-2026-24604
MEDIUM
Simple GDPR Cookie Compliance <2.0.0 - RCE
CVSS 5.3
CVE-2026-24603
MEDIUM
Universal Google Adsense and Ads Manager <1.1.9 - RCE
CVSS 5.3
CVE-2026-24598
MEDIUM
BestWebSoft Multilanguage <= 1.5.2 - RCE
CVSS 4.3
CVE-2026-24595
MEDIUM
Zoho CRM Lead Magnet <1.8.1.5 - Info Disclosure
CVSS 5.4
CVE-2026-24588
MEDIUM
Smart Product Viewer <= 1.5.4 - Missing Authorization
CVSS 4.3
CVE-2026-24587
MEDIUM
kutsy AJAX Hits Counter + Popular Posts Widget - RCE
CVSS 5.4
CVE-2026-24585
MEDIUM
Hyyan WooCommerce Polylang Integration <1.5.0 - Info Disclosure
CVSS 6.5
CVE-2026-24583
MEDIUM
SumUp Payment Gateway For WooCommerce <2.7.9 - RCE
CVSS 5.3
CVE-2026-24581
MEDIUM
Points and Rewards for WooCommerce <2.9.6 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
8,232
Exploit Likelihood
High