CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 76 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11912 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2026 | The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This… | ||
| CVE-2026-54802 | Hig | 0.49 | 7.5 | 0.00 | Jun 17, 2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. | ||
| CVE-2026-49057 | Hig | 0.49 | 7.5 | 0.00 | Jun 17, 2026 | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. | ||
| CVE-2025-69103 | Hig | 0.49 | 7.5 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions. | ||
| CVE-2026-52711 | Hig | 0.49 | 7.5 | 0.00 | Jun 16, 2026 | Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. | ||
| CVE-2026-39490 | Hig | 0.49 | 7.5 | 0.00 | Jun 16, 2026 | Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. | ||
| CVE-2025-68045 | Hig | 0.49 | 7.5 | 0.00 | Jun 16, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. | ||
| CVE-2026-49070 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. | ||
| CVE-2026-48883 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. | ||
| CVE-2026-48873 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. | ||
| CVE-2026-48835 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. | ||
| CVE-2026-42666 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | ||
| CVE-2026-40776 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. | ||
| CVE-2026-40774 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. | ||
| CVE-2026-40741 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions. | ||
| CVE-2026-39534 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions. | ||
| CVE-2026-39533 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions. | ||
| CVE-2026-39524 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions. | ||
| CVE-2026-39513 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. | ||
| CVE-2026-39503 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. |
- risk 0.49cvss 7.5epss 0.01
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.