CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,272 vulnerabilities with CWE-862
CVE-2025-66135 MEDIUM
Merkulove Imager for Elementor <2.0.5 - Info Disclosure
CVSS 5.4
CVE-2025-63018 MEDIUM
wproyal Bard <= 2.229 - Missing Authorization
CVSS 4.3
CVE-2025-62754 MEDIUM
bKash for WC <3.1.0 - Privilege Escalation
CVSS 5.3
CVE-2025-62106 MEDIUM
Mario Peshev WP-CRM System <3.4.5 - Info Disclosure
CVSS 5.4
CVE-2025-5805 MEDIUM
Ninetheme Electron <= 1.8.2 - Missing Authorization
CVSS 6.5
CVE-2025-54002 MEDIUM
Jthemes xSmart <= 1.2.9.4 - Missing Authorization
CVSS 6.5
CVE-2025-49375 MEDIUM
cozythemes HomeLancer <1.0.2 - Info Disclosure
CVSS 5.4
CVE-2025-65098 HIGH
typebot < 3.13.2 - Unauthenticated Credential Theft via Malicious Typebot Preview
CVSS 7.4
CVE-2025-15347 HIGH
The Creator LMS - Privilege Escalation
CVSS 8.8
CVE-2025-15043 MEDIUM
The Events Calendar <6.15.13 - Privilege Escalation
CVSS 5.4
CVE-2025-14798 MEDIUM
LearnPress - WordPress LMS Plugin <4.3.2.4 - Info Disclosure
CVSS 5.3
CVE-2025-14351 MEDIUM
Custom Fonts - Host Your Fonts Locally <2.1.16 - Info Disclosure
CVSS 5.3
CVE-2025-14978 MEDIUM
PeachPay - Payments & Express Checkout for WooCommerce - Info Discl...
CVSS 5.3
CVE-2025-15466 MEDIUM
WordPress Image Photo Gallery Final Tiles Grid <3.6.9 - Privilege E...
CVSS 5.4
CVE-2025-14078 MEDIUM
PAYGENT for WooCommerce <2.4.6 - Auth Bypass
CVSS 5.3
CVE-2025-14029 MEDIUM
WordPress Community Events <1.5.6 - Info Disclosure
CVSS 5.3
CVE-2025-12825 MEDIUM
WordPress Contact Form 7 <2.5 - Info Disclosure
CVSS 5.3
CVE-2025-12168 MEDIUM
Phrase TMS Integration - Info Disclosure
CVSS 4.3
CVE-2025-14463 MEDIUM
WordPress Payment Button for PayPal <=1.2.3.41 - Unauthenticated Order Creation
CVSS 5.3
CVE-2025-14450 MEDIUM
Wallet System for WooCommerce <2.7.2 - Info Disclosure
CVSS 6.5
CVE-2025-14757 MEDIUM
Cost Calculator Builder <= 3.6.9 - Unauthenticated Payment Status Bypass via complete_payment AJAX Action
CVSS 5.3
CVE-2025-14982 MEDIUM
Booking Calendar <10.14.11 - Info Disclosure
CVSS 4.3
CVE-2025-14384 MEDIUM
All in One SEO <4.9.2 - Info Disclosure
CVSS 4.3
CVE-2025-12641 MEDIUM
Awesome Support - WordPress HelpDesk & Support Plugin <6.3.6 - Auth...
CVSS 6.5
CVE-2025-64729 HIGH
AVEVA Process Optimization < 2025 - Authenticated Privilege Escalation via Project File Tampering
CVSS 8.1
Details
Vulnerabilities 8,272
Exploit Likelihood High