CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,280 vulnerabilities with CWE-862
CVE-2025-12934 HIGH
Beaver Builder - WordPress Page Builder <2.9.4.1 - Privilege Escala...
CVSS 8.1
CVE-2025-66736 HIGH
youlai-boot V2.21.1 - Improper Access Control in SysUserController ImportUsers Function
CVSS 7.1
CVE-2025-66735 HIGH
youlai-boot 2.21.1 - Privilege Escalation
CVSS 7.5
CVE-2025-14080 MEDIUM
Frontend Post Submission Manager Lite <1.2.5 - Auth Bypass
CVSS 5.3
CVE-2025-14043 MEDIUM
Tainacan plugin <1.0.2 - Auth Bypass
CVSS 5.3
CVE-2025-12980 HIGH
Post Grid Gutenberg Blocks - Info Disclosure
CVSS 7.5
CVE-2025-7782 HIGH
WP JobHunt <= 7.7 - Authenticated Stored Cross-Site Scripting via Status Parameter
CVSS 7.6
CVE-2025-14633 MEDIUM
F70 Lead Document Download <= 1.4.4 - Unauthenticated Arbitrary File Download via Media Library Attachment ID
CVSS 5.3
CVE-2025-12898 MEDIUM
Pretty Google Calendar <2.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-14455 MEDIUM
Image Photo Gallery Final Tiles Grid <3.6.7 - Auth Bypass
CVSS 5.4
CVE-2025-12361 MEDIUM
myCred WordPress <2.9.7.1 - Info Disclosure
CVSS 4.3
CVE-2025-13754 MEDIUM
Simply Schedule Appointments Booking Plugin <1.6.9.16 - Info Disclo...
CVSS 5.3
CVE-2025-66058 MEDIUM
PickPlugins Post Grid & Gutenberg Blocks <2.3.17 - RCE
CVSS 6.5
CVE-2025-63002 MEDIUM
wpforchurch Sermon Manager <2.30.0 - Info Disclosure
CVSS 5.3
CVE-2025-62961 MEDIUM
Sparkle WP Sparkle FSE <1.0.9 - RCE
CVSS 5.4
CVE-2025-62960 MEDIUM
Sparkle WP Construction Light <1.6.7 - Privilege Escalation
CVSS 5.4
CVE-2025-7047 MEDIUM
SoliClub < 5.3.7 - Missing Authorization
CVSS 4.3
CVE-2025-14618 MEDIUM
WordPress Sweet Energy Efficiency <1.0.7 - Privilege Escalation
CVSS 4.3
CVE-2025-40602 MEDIUM KEV
SonicWall SMA6200/SMA6210/SMA7200/SMA7210/SMA8200v < 12.4.3-03245 Local Privilege Escalation
CVSS 6.6
CVE-2025-14364 HIGH
Demo Importer Plus <2.0.8 - Privilege Escalation
CVSS 8.8
CVE-2025-66117 HIGH
Ays Pro Easy Form <= 2.7.8 - Missing Authorization
CVSS 7.5
CVE-2025-66104 MEDIUM
Anton Vanyukov Offload <1.9.6 - Auth Bypass
CVSS 6.5
CVE-2025-66100 MEDIUM
Magnigenie RestroPress <3.2.3.5 - Info Disclosure
CVSS 6.5
CVE-2025-66088 HIGH
PropertyHive <2.1.12 - Info Disclosure
CVSS 7.5
CVE-2025-66070 HIGH
Tomdever wpForo Forum <2.4.10 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 8,280
Exploit Likelihood High