CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,487)
page 246 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-8840 | Med | 0.34 | 5.3 | 0.00 | Aug 15, 2026 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | ||
| CVE-2026-73403 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | ||
| CVE-2026-73401 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | ||
| CVE-2026-73353 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | ||
| CVE-2026-73349 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | ||
| CVE-2026-68753 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||
| CVE-2026-66377 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted repository information under specific conditions. | ||
| CVE-2026-18035 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups. | ||
| CVE-2026-17021 | Med | 0.34 | 5.3 | 0.00 | Aug 10, 2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary… | ||
| CVE-2026-15237 | Med | 0.34 | 5.3 | 0.00 | Aug 10, 2026 | The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as… | ||
| CVE-2026-19350 | Med | 0.34 | 6.3 | 0.00 | Aug 9, 2026 | A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is… | ||
| CVE-2026-16608 | Med | 0.34 | 5.3 | 0.00 | Aug 8, 2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and… | ||
| CVE-2026-48077 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any… | ||
| CVE-2026-66701 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | ||
| CVE-2026-32548 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||
| CVE-2026-11983 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the… | ||
| CVE-2026-16290 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group,… | ||
| CVE-2026-11995 | Med | 0.34 | 5.3 | 0.00 | Aug 1, 2026 | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized… | ||
| CVE-2026-15227 | Med | 0.34 | — | 0.00 | Jul 31, 2026 | Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users. | ||
| CVE-2026-18437 | Med | 0.34 | 5.3 | 0.00 | Jul 31, 2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for… |
- risk 0.34cvss 5.3epss 0.00
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted repository information under specific conditions.
- risk 0.34cvss 5.3epss 0.00
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
- risk 0.34cvss 5.3epss 0.00
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary…
- risk 0.34cvss 5.3epss 0.00
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as…
- risk 0.34cvss 6.3epss 0.00
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…
- risk 0.34cvss 5.3epss 0.00
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and…
- risk 0.34cvss 5.3epss 0.00
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any…
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
- risk 0.34cvss 5.3epss 0.00
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the…
- risk 0.34cvss 5.3epss 0.00
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group,…
- risk 0.34cvss 5.3epss 0.00
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized…
- risk 0.34cvss —epss 0.00
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
- risk 0.34cvss 5.3epss 0.00
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for…