The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,272 vulnerabilities with CWE-862
CVE-2025-14371
MEDIUM
Tag, Category, Taxonomy Manager - AI Autotagger <3.41.0 - Privilege...
CVSS 4.3
CVE-2025-13812
MEDIUM
GamiPress < 7.6.1 - Authenticated Unauthorized Data Access via AJAX Functions
CVSS 4.3
CVE-2025-14441
MEDIUM
Popupkit plugin - Privilege Escalation
CVSS 4.3
CVE-2025-14034
MEDIUM
ilGhera Support System <1.2.6 - Privilege Escalation
CVSS 5.3
CVE-2025-11370
MEDIUM
Popup & Slider Builder <4.0.7 - Info Disclosure
CVSS 5.3
CVE-2025-46255
HIGH
Marketing Fire LLC LoginWP - Pro <4.0.8.5 - Info Disclosure
CVSS 7.5
CVE-2025-39561
MEDIUM
Marketing Fire, LLC LoginWP - Pro <4.0.8.5 - Info Disclosure
CVSS 6.5
CVE-2025-68850
HIGH
Codepeople Sell Downloads <1.1.12 - RCE
CVSS 7.5
CVE-2025-68547
HIGH
WPweb Follow My Blog Post <2.4.0 - Info Disclosure
CVSS 7.5
CVE-2025-31046
MEDIUM
WPvibes AnyWhere Elementor Pro <2.29 - RCE
CVSS 4.3
CVE-2025-12519
MEDIUM
Centreon Infra Monitoring <25.10.2 - Info Disclosure
CVSS 5.3
CVE-2025-15235
MEDIUM
QOCA aim < 2.7.6 - Authenticated Missing Authorization via Network Packet Parameter Modification
CVSS 6.5
CVE-2025-15115
MEDIUM
Petlibro < 1.7.31 - Unauthenticated Authentication Bypass via OAuth Token Validation Flaw
CVSS 6.5
CVE-2025-34171
MEDIUM
CasaOS <= 0.4.15 - Unauthenticated Sensitive Information Exposure via Image and Debug Endpoints
CVSS 5.3
CVE-2025-14047
MEDIUM
WP User Frontend <4.2.4 - Info Disclosure
CVSS 5.3
CVE-2025-15406
MEDIUM
PHPGurukul Online Course Registration < 3.1 - Missing Authorization
CVSS 6.3
CVE-2025-14428
MEDIUM
My Sticky Elements <2.3.3 - Info Disclosure
CVSS 4.3
CVE-2025-15405
MEDIUM
phpems < 11.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-66148
MEDIUM
Merkulove Conformer for Elementor <1.0.8 - Info Disclosure
CVSS 5.4
CVE-2025-66146
MEDIUM
Merkulove Logger for Elementor <1.0.9 - RCE
CVSS 5.4
CVE-2025-66145
MEDIUM
Merkulove Worker <1.1.1 - Info Disclosure
CVSS 5.4
CVE-2025-66144
MEDIUM
Merkulove Worker for Elementor <1.0.10 - Privilege Escalation
CVSS 5.4
CVE-2025-66153
MEDIUM
Merkulove Headinger for Elementor <1.1.4 - Info Disclosure
CVSS 5.4
CVE-2025-66152
MEDIUM
Merkulove Criptopayer <1.0.1 - Info Disclosure
CVSS 5.4
CVE-2025-66151
MEDIUM
Merkulove Countdowner for Elementor <1.0.5 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
8,272
Exploit Likelihood
High