The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,281 vulnerabilities with CWE-862
CVE-2025-14397
HIGH
Postem Ipsum <3.0.1 - Privilege Escalation
CVSS 8.8
CVE-2025-14395
MEDIUM
Popover Windows <1.3 - Info Disclosure
CVSS 4.3
CVE-2025-14367
MEDIUM
Easy Theme Options <1.0 - Auth Bypass
CVSS 5.3
CVE-2025-14366
MEDIUM
Eyewear prescription form plugin <6.0.1 - Auth Bypass
CVSS 5.3
CVE-2025-14365
MEDIUM
Eyewear plugin <6.0.1 - Auth Bypass
CVSS 5.3
CVE-2025-14288
MEDIUM
WordPress Gallery Blocks <3.3.0 - Privilege Escalation
CVSS 4.3
CVE-2025-13403
MEDIUM
Employee Spotlight <5.1.3 - Privilege Escalation
CVSS 4.3
CVE-2025-13093
MEDIUM
Devs CRM < 1.1.8 - Unauthenticated Data Modification via Bulk Update REST-API Endpoint
CVSS 5.3
CVE-2025-13092
MEDIUM
Devs CRM < 1.1.8 - Unauthenticated Sensitive Data Exposure via REST API Endpoint
CVSS 5.3
CVE-2025-12362
MEDIUM
myCred <= 2.9.7 - Unauthenticated Missing Authorization via cashcred_pay_now
CVSS 5.3
CVE-2025-11164
MEDIUM
Mavix Education <1.0 - Privilege Escalation
CVSS 4.3
CVE-2025-43497
MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.2
CVE-2025-14065
MEDIUM
Simple Bike Rental <1.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-14074
MEDIUM
Contact Form 7 + Drag and Drop Template Builder <6.3.3 - Info Discl...
CVSS 4.3
CVE-2025-10583
LOW
WP Fastest Cache Premium <= 1.7.4 - Authenticated Server-Side Request Forgery via get_server_time_ajax_request
CVSS 3.5
CVE-2025-67737
LOW
AzuraCast < 0.23.2 - Missing Authorization in SFTP API Endpoint
CVSS 3.1
CVE-2025-12655
MEDIUM
Hippoo Mobile App <1.7.1 - Code Injection
CVSS 5.3
CVE-2025-14392
MEDIUM
Simple Theme Changer <1.0 - Info Disclosure
CVSS 4.3
CVE-2025-14170
MEDIUM
Vimeo SimpleGallery <0.2 - Auth Bypass
CVSS 4.3
CVE-2025-14064
MEDIUM
BuddyTask <1.3.0 - Privilege Escalation
CVSS 5.4
CVE-2025-14045
MEDIUM
URL Media Uploader <1.0.1 - Auth Bypass
CVSS 4.3
CVE-2025-13866
MEDIUM
Flow-Flow Social Feed Stream <4.7.5 - Info Disclosure
CVSS 6.4
CVE-2025-13440
MEDIUM
Premmerce Wishlist <1.1.10 - Auth Bypass
CVSS 5.3
CVE-2025-13334
HIGH
Blaze Demo Importer <1.0.13 - Privilege Escalation
CVSS 8.1
CVE-2025-13314
MEDIUM
WooCommerce Filter Plus <1.1.5 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,281
Exploit Likelihood
High