The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,324 vulnerabilities with CWE-862
CVE-2025-62028
MEDIUM
ThemeNectar Salient - Info Disclosure
CVSS 4.3
CVE-2025-62018
MEDIUM
Hogash Kallyas <4.22.0 - Info Disclosure
CVSS 5.3
CVE-2025-62017
MEDIUM
hogash Kallyas <4.22.0 - Info Disclosure
CVSS 5.4
CVE-2025-60247
MEDIUM
Bux Bux Woocommerce <1.2.4 - Info Disclosure
CVSS 6.5
CVE-2025-5803
MEDIUM
e4jvikwp VikBooking Hotel Booking Engine & PMS <1.8.3 - Info Disclo...
CVSS 5.3
CVE-2025-58986
MEDIUM
Ganddser JOAN <6.0.4 - Privilege Escalation
CVSS 6.5
CVE-2025-58629
HIGH
Miraculous < 2.0.9 - Info Disclosure
CVSS 7.5
CVE-2025-58243
MEDIUM
Jthemes imEvent <= 3.4.0 - Info Disclosure
CVSS 5.3
CVE-2025-58207
HIGH
WP Messiah Ai Image Alt Text Generator <1.1.5 - Info Disclosure
CVSS 8.2
CVE-2025-54711
HIGH
bPlugins Info Cards <= 1.0.11 - Missing Authorization
CVSS 7.1
CVE-2025-53246
MEDIUM
Gaurav Aggarwal Backup and Move <0.1 - Auth Bypass
CVSS 6.5
CVE-2025-53214
MEDIUM
Sertifier Certificate & Badge Maker <1.22 - RCE
CVSS 6.5
CVE-2025-49394
HIGH
bPlugins Image Gallery <1.0.8 - Info Disclosure
CVSS 7.1
CVE-2025-39465
MEDIUM
flippercode Advanced Google Maps <5.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-12563
MEDIUM
Blog2Social <8.6.0 - Limited File Upload
CVSS 4.3
CVE-2025-64171
HIGH
marin3r <= 0.13.3 - Missing Authorization via DiscoveryServiceCertificate
CVE-2025-12469
MEDIUM
FunnelKit Automations < 3.6.4.1 - Authenticated Missing Authorization via bwfan_test_email AJAX Handler
CVSS 4.3
CVE-2025-12675
MEDIUM
KiotViet Sync <1.8.5 - Info Disclosure
CVSS 4.3
CVE-2025-12384
HIGH
Document Embedder <2.0.0 - Info Disclosure
CVSS 8.6
CVE-2025-11373
MEDIUM
Depicter Popup & Slider Builder <4.0.4 - RCE
CVSS 4.3
CVE-2025-11835
MEDIUM
Paid Membership Subscriptions <2.16.4 - Info Disclosure
CVSS 5.3
CVE-2025-12582
MEDIUM
WordPress Features <0.0.3 - Info Disclosure
CVSS 4.3
CVE-2025-63294
MEDIUM
WorkDo HRM <8.1 - Privilege Escalation
CVSS 6.5
CVE-2025-41345
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_denuncia and id_user Parameters
CVSS 7.5
CVE-2025-41344
HIGH
canaldenuncia.app < 4.4.8 - Unauthenticated Information Disclosure via id_archivo Parameter
CVSS 7.5
Details
Vulnerabilities
8,324
Exploit Likelihood
High