CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,267)
page 435 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66751 | Med | 0.00 | 5.4 | 0.00 | Jul 28, 2026 | Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms… | ||
| CVE-2026-66750 | Med | 0.00 | 4.3 | 0.00 | Jul 28, 2026 | Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval… | ||
| CVE-2026-16774 | Med | 0.00 | 5.3 | 0.00 | Jul 28, 2026 | The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and… | ||
| CVE-2026-15411 | Med | 0.00 | 5.3 | 0.00 | Jul 28, 2026 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is… | ||
| CVE-2026-15025 | Hig | 0.00 | 7.5 | 0.01 | Jul 28, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch,… | ||
| CVE-2026-13110 | Med | 0.00 | 5.3 | 0.00 | Jul 28, 2026 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and… | ||
| CVE-2026-14168 | — | Hig | 0.00 | 8.8 | 0.00 | Jul 28, 2026 | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access. | |
| CVE-2026-16587 | Med | 0.00 | 4.3 | 0.00 | Jul 28, 2026 | The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-14924 | Hig | 0.00 | 7.5 | 0.00 | Jul 28, 2026 | The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages. | ||
| CVE-2026-14821 | Low | 0.00 | 2.7 | 0.00 | Jul 28, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. | ||
| CVE-2026-12124 | Med | 0.00 | 5.3 | 0.00 | Jul 28, 2026 | The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST… | ||
| CVE-2026-66473 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | ||
| CVE-2026-65445 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | ||
| CVE-2026-43665 | Med | 0.00 | 5.5 | 0.00 | Jul 27, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing. | ||
| CVE-2026-65922 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level;… | ||
| CVE-2026-66477 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Gillion <= 4.13 versions. | ||
| CVE-2026-66442 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | ||
| CVE-2026-65568 | Med | 0.00 | 5.0 | 0.00 | Jul 27, 2026 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | ||
| CVE-2026-65567 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | ||
| CVE-2026-65435 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. |
- risk 0.00cvss 5.4epss 0.00
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms…
- risk 0.00cvss 4.3epss 0.00
Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval…
- risk 0.00cvss 5.3epss 0.00
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and…
- risk 0.00cvss 5.3epss 0.00
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is…
- risk 0.00cvss 7.5epss 0.01
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch,…
- risk 0.00cvss 5.3epss 0.00
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and…
- risk 0.00cvss 8.8epss 0.00
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
- risk 0.00cvss 4.3epss 0.00
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 7.5epss 0.00
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
- risk 0.00cvss 2.7epss 0.00
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
- risk 0.00cvss 5.3epss 0.00
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST…
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
- risk 0.00cvss 5.5epss 0.00
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.
- risk 0.00cvss 7.1epss 0.00
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level;…
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
- risk 0.00cvss 5.0epss 0.00
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.