CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 450 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12557 | Med | 0.00 | 5.3 | 0.00 | Jul 3, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated… | ||
| CVE-2026-12729 | Med | 0.00 | 4.3 | 0.00 | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the… | ||
| CVE-2026-59097 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can… | ||
| CVE-2026-57760 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29. | ||
| CVE-2026-57750 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. | ||
| CVE-2026-57746 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Booked <= 3.0.0 versions. | ||
| CVE-2026-57731 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Broken Access Control in Flatsome <= 3.20.5 versions. | ||
| CVE-2026-57730 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. | ||
| CVE-2026-57689 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions. | ||
| CVE-2026-57688 | Hig | 0.00 | 8.2 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. | ||
| CVE-2026-57685 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions. | ||
| CVE-2026-57669 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | ||
| CVE-2026-57355 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | ||
| CVE-2026-57353 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions. | ||
| CVE-2026-39448 | Hig | 0.00 | 7.5 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. | ||
| CVE-2026-27433 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in Motors <= 5.6.80 versions. | ||
| CVE-2025-69134 | Hig | 0.00 | 7.5 | 0.00 | Jul 2, 2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | ||
| CVE-2025-66076 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions. | ||
| CVE-2026-13459 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | ||
| CVE-2026-12472 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes… |
- risk 0.00cvss 5.3epss 0.00
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…
- risk 0.00cvss 4.3epss 0.00
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the…
- risk 0.00cvss 5.3epss 0.00
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can…
- risk 0.00cvss 5.3epss 0.00
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
- risk 0.00cvss 8.2epss 0.00
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
- risk 0.00cvss 5.3epss 0.00
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
- risk 0.00cvss 5.3epss 0.00
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…