The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,280 vulnerabilities with CWE-862
CVE-2025-12934
HIGH
Beaver Builder - WordPress Page Builder <2.9.4.1 - Privilege Escala...
CVSS 8.1
CVE-2025-66736
HIGH
youlai-boot V2.21.1 - Improper Access Control in SysUserController ImportUsers Function
CVSS 7.1
CVE-2025-66735
HIGH
youlai-boot 2.21.1 - Privilege Escalation
CVSS 7.5
CVE-2025-14080
MEDIUM
Frontend Post Submission Manager Lite <1.2.5 - Auth Bypass
CVSS 5.3
CVE-2025-14043
MEDIUM
Tainacan plugin <1.0.2 - Auth Bypass
CVSS 5.3
CVE-2025-12980
HIGH
Post Grid Gutenberg Blocks - Info Disclosure
CVSS 7.5
CVE-2025-7782
HIGH
WP JobHunt <= 7.7 - Authenticated Stored Cross-Site Scripting via Status Parameter
CVSS 7.6
CVE-2025-14633
MEDIUM
F70 Lead Document Download <= 1.4.4 - Unauthenticated Arbitrary File Download via Media Library Attachment ID
CVSS 5.3
CVE-2025-12898
MEDIUM
Pretty Google Calendar <2.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-14455
MEDIUM
Image Photo Gallery Final Tiles Grid <3.6.7 - Auth Bypass
CVSS 5.4
CVE-2025-12361
MEDIUM
myCred WordPress <2.9.7.1 - Info Disclosure
CVSS 4.3
CVE-2025-13754
MEDIUM
Simply Schedule Appointments Booking Plugin <1.6.9.16 - Info Disclo...
CVSS 5.3
CVE-2025-66058
MEDIUM
PickPlugins Post Grid & Gutenberg Blocks <2.3.17 - RCE
CVSS 6.5
CVE-2025-63002
MEDIUM
wpforchurch Sermon Manager <2.30.0 - Info Disclosure
CVSS 5.3
CVE-2025-62961
MEDIUM
Sparkle WP Sparkle FSE <1.0.9 - RCE
CVSS 5.4
CVE-2025-62960
MEDIUM
Sparkle WP Construction Light <1.6.7 - Privilege Escalation
CVSS 5.4
CVE-2025-7047
MEDIUM
SoliClub < 5.3.7 - Missing Authorization
CVSS 4.3
CVE-2025-14618
MEDIUM
WordPress Sweet Energy Efficiency <1.0.7 - Privilege Escalation
CVSS 4.3
CVE-2025-40602
MEDIUM
KEV
SonicWall SMA6200/SMA6210/SMA7200/SMA7210/SMA8200v < 12.4.3-03245 Local Privilege Escalation
CVSS 6.6
CVE-2025-14364
HIGH
Demo Importer Plus <2.0.8 - Privilege Escalation
CVSS 8.8
CVE-2025-66117
HIGH
Ays Pro Easy Form <= 2.7.8 - Missing Authorization
CVSS 7.5
CVE-2025-66104
MEDIUM
Anton Vanyukov Offload <1.9.6 - Auth Bypass
CVSS 6.5
CVE-2025-66100
MEDIUM
Magnigenie RestroPress <3.2.3.5 - Info Disclosure
CVSS 6.5
CVE-2025-66088
HIGH
PropertyHive <2.1.12 - Info Disclosure
CVSS 7.5
CVE-2025-66070
HIGH
Tomdever wpForo Forum <2.4.10 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
8,280
Exploit Likelihood
High