CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,272 vulnerabilities with CWE-862
CVE-2025-14782 MEDIUM
Forminator Forms < 1.49.1 - Authenticated Authorization Bypass via CSV Export Function
CVSS 5.3
CVE-2025-14720 MEDIUM
Amelia plugin <1.2.38 - Info Disclosure
CVSS 5.3
CVE-2025-14718 MEDIUM
Schedule Post Changes With PublishPress Future <4.9.3 - Auth Bypass
CVSS 5.4
CVE-2025-14886 MEDIUM
Japanized for WooCommerce <2.7.17 - Info Disclosure
CVSS 5.3
CVE-2025-67926 MEDIUM
Shahjahan Jewel Fluent Support <=1.10.4 - Info Disclosure
CVSS 6.5
CVE-2025-67917 MEDIUM
Shinetheme Traveler <3.2.6 - Info Disclosure
CVSS 6.5
CVE-2025-67913 MEDIUM
Aruba HiSpeed Cache < 3.0.3 - Info Disclosure
CVSS 6.5
CVE-2025-22715 HIGH
WP Attractive Donations System <1.26 - RCE
CVSS 7.5
CVE-2025-14360 HIGH
Kaira Blockons <1.2.15 - Info Disclosure
CVSS 7.5
CVE-2025-14358 HIGH
REHub Framework <20 - Info Disclosure
CVSS 7.5
CVE-2025-13679 MEDIUM
Tutor LMS < 3.9.3 - Authenticated Missing Authorization in get_order_by_id()
CVSS 6.5
CVE-2025-12640 MEDIUM
Folders - Unlimited Folders to Organize Media Library Folder, Pages...
CVSS 4.3
CVE-2025-69221 MEDIUM
LibreChat 0.8.1-rc2 - Authenticated Improper Access Control via Agent Permissions Query
CVSS 4.3
CVE-2025-69220 HIGH
LibreChat 0.8.1-rc2 - Authenticated Improper Access Control in File Upload and Search
CVSS 7.1
CVE-2025-46434 MEDIUM
POSIMYTH Innovation The Plus Addons for Elementor Pro <6.3.7 - Priv...
CVSS 6.5
CVE-2025-69344 MEDIUM
ThemeHunk Oneline Lite <6.6 - Info Disclosure
CVSS 4.3
CVE-2025-69333 MEDIUM
Crocoblock JetEngine <3.8.1.1 - RCE
CVSS 4.3
CVE-2025-14901 MEDIUM
Bit Form - Contact Form Plugin <2.21.6 - Unauthorized Workflow Exec...
CVSS 6.5
CVE-2025-14460 MEDIUM
Piraeus Bank WooCommerce Payment Gateway <3.1.4 - Info Disclosure
CVSS 5.3
CVE-2025-14370 MEDIUM
Quote Comments <3.0.0 - Auth Bypass
CVSS 4.3
CVE-2025-14070 HIGH
Reviewify WordPress <1.0.6 - Info Disclosure
CVSS 7.5
CVE-2025-13722 MEDIUM
Fluent Forms < 6.1.7 - Authenticated Missing Authorization via AI Form Builder
CVSS 5.3
CVE-2025-13529 MEDIUM
Unify WordPress <3.4.9 - Info Disclosure
CVSS 5.3
CVE-2025-13496 MEDIUM
Moosend Landing Pages <1.1.7 - Info Disclosure
CVSS 5.3
CVE-2025-13493 HIGH
Latest Registered Users <= 1.4 - Unauthenticated User Data Export via CSV Action Parameter
CVSS 7.5
Details
Vulnerabilities 8,272
Exploit Likelihood High