The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,281 vulnerabilities with CWE-862
CVE-2025-64244
MEDIUM
Restrict Elementor Widgets - Auth Bypass
CVSS 4.3
CVE-2025-64243
MEDIUM
e-plugins Directory Pro <2.5.6 - Info Disclosure
CVSS 4.3
CVE-2025-64242
MEDIUM
Merv Barrett Easy Property Listings <3.5.15 - RCE
CVSS 4.3
CVE-2025-64241
MEDIUM
WP Coupons and Deals <= 3.2.4 - Missing Authorization
CVSS 4.3
CVE-2025-64238
MEDIUM
NicolasKulka WPS Bidouille <= 1.33.1 - Info Disclosure
CVSS 4.3
CVE-2025-59001
MEDIUM
ThemeNectar Salient Core <3.0.8 - Info Disclosure
CVSS 4.3
CVE-2025-54045
MEDIUM
CM On Demand Search And Replace <1.5.5 - RCE
CVSS 4.3
CVE-2025-54005
MEDIUM
sonalsinha21 SKT Page Builder <= 4.9 - Info Disclosure
CVSS 4.3
CVE-2025-54004
LOW
WC Lovers WCFM - Frontend Manager for WooCommerce <= 6.7.21 - Info ...
CVSS 2.7
CVE-2025-11991
MEDIUM
JetFormBuilder <3.5.3 - Info Disclosure
CVSS 5.3
CVE-2025-13794
MEDIUM
Auto Featured Image <= 4.2.1 - Authenticated Data Modification via bulk_action_generate_handler
CVSS 4.3
CVE-2025-12809
MEDIUM
Dokan Pro <= 4.1.3 - Unauthenticated Sensitive Data Exposure via REST API
CVSS 5.3
CVE-2025-13956
MEDIUM
LearnPress - WordPress LMS Plugin <4.3.1 - Info Disclosure
CVSS 5.3
CVE-2025-66402
MEDIUM
Misskey <2025.12.0 - Info Disclosure
CVSS 6.5
CVE-2025-14038
HIGH
EDB Hybrid Manager < 1.3.3 and < 2025.12.0 - Unauthenticated Missing Authorization via gRPC Endpoints
CVSS 7.0
CVE-2025-65742
HIGH
Newgen OmniDocs v11.0 - Info Disclosure
CVSS 8.2
CVE-2025-14003
MEDIUM
Image Gallery - Photo Grid & Video Gallery <2.13.3 - Info Disclosure
CVSS 4.3
CVE-2025-13950
MEDIUM
OneSignal - Web Push Notifications <3.6.1 - Info Disclosure
CVSS 5.3
CVE-2025-12900
MEDIUM
FileBird - WordPress Media Library Folders & File Manager <6.5.1 - ...
CVSS 4.3
CVE-2025-9218
LOW
rtMedia for WordPress, BuddyPress and bbPress 4.7.0-4.7.3 - Unauthenticated Information Disclosure
CVSS 3.7
CVE-2025-14581
MEDIUM
HAPPY - Helpdesk Support Ticket System <1.0.9 - Auth Bypass
CVSS 4.3
CVE-2025-14540
MEDIUM
Userback < 1.0.15 - Authenticated Unauthorized Data Access via userback_get_json Function
CVSS 4.3
CVE-2025-14508
MEDIUM
MediaCommander - WordPress <2.3.1 - Privilege Escalation
CVSS 6.5
CVE-2025-14447
MEDIUM
WordPress AnnunciFunebri Impresa <4.7.0 - Info Disclosure
CVSS 4.3
CVE-2025-14446
MEDIUM
WordPress Popup Builder <1.1.37 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
8,281
Exploit Likelihood
High