The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,272 vulnerabilities with CWE-862
CVE-2025-13419
MEDIUM
WP Front User Submit <5.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-12449
MEDIUM
aBlocks - WordPress Gutenberg Blocks <2.4.0 - Info Disclosure
CVSS 5.4
CVE-2025-11877
HIGH
User Activity Log <2.2 - Info Disclosure
CVSS 7.5
CVE-2025-69364
MEDIUM
Cloudways Breeze <= 2.2.21 - Missing Authorization
CVSS 5.3
CVE-2025-69363
MEDIUM
Responsive Addons for Elementor <2.0.9 - Info Disclosure
CVSS 6.5
CVE-2025-69361
MEDIUM
PublishPress Post Expirator <5.0 - Info Disclosure
CVSS 4.3
CVE-2025-69359
MEDIUM
WPFunnels Creator LMS <1.1.12 - Info Disclosure
CVSS 5.3
CVE-2025-69355
MEDIUM
Tickera <= 3.5.6.4 - Missing Authorization
CVSS 4.3
CVE-2025-69354
MEDIUM
BBR Plugins Better Business Reviews <0.1.2 - RCE
CVSS 4.3
CVE-2025-69353
MEDIUM
Proxy & VPN Blocker <3.5.4 - Info Disclosure
CVSS 4.3
CVE-2025-69352
MEDIUM
StellarWP The Events Calendar <= 6.15.12.2 - Info Disclosure
CVSS 5.4
CVE-2025-69349
MEDIUM
RSS Feed Widget <= 3.0.2 - Missing Authorization
CVSS 5.4
CVE-2025-69348
MEDIUM
CoolHappy The Events Calendar Countdown Addon <= 1.4.15 - Info Disc...
CVSS 4.3
CVE-2025-69346
MEDIUM
WPCenter AffiliateX <= 1.3.9.3 - Missing Authorization
CVSS 4.3
CVE-2025-69345
MEDIUM
BoldGrid Post and Page Builder <1.27.9 - RCE
CVSS 4.3
CVE-2025-69341
MEDIUM
BuddhaThemes WeDesignTech Ultimate Booking Addon <1.0.4 - RCE
CVSS 5.4
CVE-2025-69336
MEDIUM
Ultimate Store Kit Elementor Addons <2.9.5 - Auth Bypass
CVSS 4.3
CVE-2025-69331
MEDIUM
Theater for WordPress <0.20 - Auth Bypass
CVSS 4.3
CVE-2025-69327
MEDIUM
Car Rental Manager <= 1.0.9 - Missing Authorization
CVSS 4.3
CVE-2025-39477
CRITICAL
Sfwebservice InWave Jobs <3.5.8 - Info Disclosure
CVSS 9.8
CVE-2025-9637
MEDIUM
Quiz and Survey Master (QSM) <= 10.3.1 - Unauthenticated Unpublished Quiz Access and File Upload
CVSS 6.5
CVE-2025-9294
MEDIUM
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated Unauthorized Data Deletion via qsm_dashboard_delete_result
CVSS 4.3
CVE-2025-5919
MEDIUM
WP Timetics <1.0.36 - Info Disclosure
CVSS 6.5
CVE-2025-13964
MEDIUM
LearnPress - WordPress LMS Plugin <4.3.2 - Info Disclosure
CVSS 5.3
CVE-2025-13766
MEDIUM
MasterStudy LMS WordPress Plugin - Unauthorized Data Modification
CVSS 5.4
Details
Vulnerabilities
8,272
Exploit Likelihood
High