CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,323 vulnerabilities with CWE-862
CVE-2025-12392 MEDIUM
Cryptocurrency Payment Gateway for WooCommerce <2.0.22 - Info Discl...
CVSS 5.3
CVE-2025-12391 MEDIUM
Restrictions for BuddyPress <1.5.2 - Info Disclosure
CVSS 5.3
CVE-2025-11734 MEDIUM
AIOSEO - WordPress Plugin <1.2.5 - Unauthorized Post Modification
CVSS 5.4
CVE-2025-12961 MEDIUM
WordPress Download Panel <1.3.3 - Privilege Escalation
CVSS 4.3
CVE-2025-12937 MEDIUM
ACF Flexible Layouts Manager <1.1.6 - Info Disclosure
CVSS 6.5
CVE-2025-12372 MEDIUM
Permalinks Cascade <2.2 - Auth Bypass
CVSS 4.3
CVE-2025-11620 HIGH
Multiple Roles per User plugin - Info Disclosure
CVSS 7.2
CVE-2025-6171 MEDIUM
GitLab 13.2-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Missing Authorization via Packages API
CVSS 5.3
CVE-2025-12849 MEDIUM
Contest Gallery <28.0.2 - Auth Bypass
CVSS 5.3
CVE-2025-12847 MEDIUM
All in One SEO <4.8.9 - Privilege Escalation
CVSS 4.3
CVE-2025-13179 MEDIUM
Bdtask Wholesale < 2025-10-16 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-13177 MEDIUM
Bdtask SalesERP < 2025-10-16 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-13119 MEDIUM
Simple E-Banking System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-12817 LOW
PostgreSQL <18.1, 17.7, 16.11, 15.15, 14.20, 13.23 - DoS
CVSS 3.1
CVE-2025-12377 MEDIUM
Envira Photo Gallery <1.12.0 - Info Disclosure
CVSS 4.3
CVE-2025-64384 MEDIUM
JetFormBuilder <= 3.5.3 - Missing Authorization
CVSS 5.3
CVE-2025-64382 MEDIUM
Order Export & Order Import for WooCommerce <2.6.7 - Info Disclosure
CVSS 4.3
CVE-2025-64379 MEDIUM
Booster for WooCommerce <= 7.4.0 - Missing Authorization
CVSS 4.3
CVE-2025-64370 MEDIUM
YOP Poll <= 6.5.38 - Missing Authorization
CVSS 5.3
CVE-2025-64369 MEDIUM
Contact Form Email <= 1.3.58 - Missing Authorization
CVSS 6.5
CVE-2025-64277 MEDIUM
QuantumCloud ChatBot <= 7.3.9 - Missing Authorization
CVSS 5.3
CVE-2025-64276 MEDIUM
Ays Pro Survey Maker <5.1.9.4 - RCE
CVSS 6.5
CVE-2025-64274 MEDIUM
WPKoi Templates for Elementor <3.4.4 - Info Disclosure
CVSS 4.3
CVE-2025-64269 MEDIUM
WooCommerce PDF Invoice Builder <1.2.150 - RCE
CVSS 4.3
CVE-2025-64265 MEDIUM
N-Media Frontend File Manager <23.2 - RCE
CVSS 4.3
Details
Vulnerabilities 8,323
Exploit Likelihood High