CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,272 vulnerabilities with CWE-862
CVE-2025-14371 MEDIUM
Tag, Category, Taxonomy Manager - AI Autotagger <3.41.0 - Privilege...
CVSS 4.3
CVE-2025-13812 MEDIUM
GamiPress < 7.6.1 - Authenticated Unauthorized Data Access via AJAX Functions
CVSS 4.3
CVE-2025-14441 MEDIUM
Popupkit plugin - Privilege Escalation
CVSS 4.3
CVE-2025-14034 MEDIUM
ilGhera Support System <1.2.6 - Privilege Escalation
CVSS 5.3
CVE-2025-11370 MEDIUM
Popup & Slider Builder <4.0.7 - Info Disclosure
CVSS 5.3
CVE-2025-46255 HIGH
Marketing Fire LLC LoginWP - Pro <4.0.8.5 - Info Disclosure
CVSS 7.5
CVE-2025-39561 MEDIUM
Marketing Fire, LLC LoginWP - Pro <4.0.8.5 - Info Disclosure
CVSS 6.5
CVE-2025-68850 HIGH
Codepeople Sell Downloads <1.1.12 - RCE
CVSS 7.5
CVE-2025-68547 HIGH
WPweb Follow My Blog Post <2.4.0 - Info Disclosure
CVSS 7.5
CVE-2025-31046 MEDIUM
WPvibes AnyWhere Elementor Pro <2.29 - RCE
CVSS 4.3
CVE-2025-12519 MEDIUM
Centreon Infra Monitoring <25.10.2 - Info Disclosure
CVSS 5.3
CVE-2025-15235 MEDIUM
QOCA aim < 2.7.6 - Authenticated Missing Authorization via Network Packet Parameter Modification
CVSS 6.5
CVE-2025-15115 MEDIUM
Petlibro < 1.7.31 - Unauthenticated Authentication Bypass via OAuth Token Validation Flaw
CVSS 6.5
CVE-2025-34171 MEDIUM
CasaOS <= 0.4.15 - Unauthenticated Sensitive Information Exposure via Image and Debug Endpoints
CVSS 5.3
CVE-2025-14047 MEDIUM
WP User Frontend <4.2.4 - Info Disclosure
CVSS 5.3
CVE-2025-15406 MEDIUM
PHPGurukul Online Course Registration < 3.1 - Missing Authorization
CVSS 6.3
CVE-2025-14428 MEDIUM
My Sticky Elements <2.3.3 - Info Disclosure
CVSS 4.3
CVE-2025-15405 MEDIUM
phpems < 11.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-66148 MEDIUM
Merkulove Conformer for Elementor <1.0.8 - Info Disclosure
CVSS 5.4
CVE-2025-66146 MEDIUM
Merkulove Logger for Elementor <1.0.9 - RCE
CVSS 5.4
CVE-2025-66145 MEDIUM
Merkulove Worker <1.1.1 - Info Disclosure
CVSS 5.4
CVE-2025-66144 MEDIUM
Merkulove Worker for Elementor <1.0.10 - Privilege Escalation
CVSS 5.4
CVE-2025-66153 MEDIUM
Merkulove Headinger for Elementor <1.1.4 - Info Disclosure
CVSS 5.4
CVE-2025-66152 MEDIUM
Merkulove Criptopayer <1.0.1 - Info Disclosure
CVSS 5.4
CVE-2025-66151 MEDIUM
Merkulove Countdowner for Elementor <1.0.5 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 8,272
Exploit Likelihood High