CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,954 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 101 of 180
- CVE-2025-14901MEDIUMCVSS 6.5EG 6.52026-01-07
The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic fl…
- CVE-2025-14913MEDIUMCVSS 5.3EG 5.32025-12-26
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions u…
- CVE-2025-14944MEDIUMCVSS 5.3EG 5.32026-04-07
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verifi…
- CVE-2025-14947MEDIUMCVSS 6.5EG 6.52026-01-23
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_call…
- CVE-2025-14948MEDIUMCVSS 5.3EG 5.32026-01-10
The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions …
- CVE-2025-14971MEDIUMCVSS 5.3EG 5.32026-01-27
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createPartialPayment and cancelPartialPayment functions in all versions up to, and in…
- CVE-2025-14978MEDIUMCVSS 5.3EG 5.32026-01-20
The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay web…
- CVE-2025-14982MEDIUMCVSS 4.3EG 4.32026-01-16
The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-…
- CVE-2025-1502MEDIUMCVSS 5.3EG 5.32025-03-01
The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in all versions up to, and including, 1.33.3. This…
- CVE-2025-1504MEDIUMCVSS 4.3EG 4.32025-03-08
The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due to insufficient restrictions on which posts can be included. This makes it p…
- CVE-2025-15041HIGHCVSS 7.2EG 7.22026-02-19
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all ve…
- CVE-2025-15043MEDIUMCVSS 5.4EG 5.42026-01-20
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.1…
- CVE-2025-15066MEDIUMCVSS 6.2EG 6.22025-12-29
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the "exam" directory exists under th…
- CVE-2025-15068HIGHCVSS 7.7EG 7.72025-12-29
Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 before 3.0.1
- CVE-2025-1507MEDIUMCVSS 5.3EG 5.32025-03-14
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() function in all versions up to, and including, 3.2.1. This makes…
- CVE-2025-15070MEDIUMCVSS 5.5EG 5.52025-12-29
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse. This issue affects Web Fax: from 3.0 before 3.0.1
- CVE-2025-1508MEDIUMCVSS 5.3EG 5.32025-03-12
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.14. This makes it possible for authenticated atta…
- CVE-2025-15115CRITICALCVSS 9.8EG 9.82026-01-04
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system…
- CVE-2025-15157HIGHCVSS 8.8EG 8.82026-02-13
The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' …
- CVE-2025-15235MEDIUMCVSS 6.5EG 6.52026-01-05
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access ot…
- CVE-2025-15260MEDIUMCVSS 6.5EG 6.52026-02-04
The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorize…
- CVE-2025-1528MEDIUMCVSS 4.3EG 4.32025-03-14
The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function in all versions up to, and including, 2.5.19. This makes it possible for authenti…
- CVE-2025-15285HIGHCVSS 7.5EG 7.52026-02-04
The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and in…
- CVE-2025-15289LOWCVSS 3.1EG 3.12026-02-05
Tanium addressed an improper access controls vulnerability in Interact.
- CVE-2025-15326MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an improper access controls vulnerability in Patch.
- CVE-2025-15327MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an improper access controls vulnerability in Deploy.
- CVE-2025-15330HIGHCVSS 8.8EG 8.82026-02-05
Tanium addressed an improper input validation vulnerability in Deploy.
- CVE-2025-15347HIGHCVSS 8.8EG 8.82026-01-20
The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_ch…
- CVE-2025-15369MEDIUMCVSS 5.3EG 5.32026-05-20
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This m…
- CVE-2025-15390MEDIUMCVSS 6.3EG 6.32025-12-31
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploi…
- CVE-2025-15400MEDIUMCVSS 6.5EG 6.52026-02-11
The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, su…
- CVE-2025-15405MEDIUMCVSS 8.8EG 4.32026-01-01
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.
- CVE-2025-15406MEDIUMCVSS 8.8EG 6.32026-01-01
A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and m…
- CVE-2025-15445MEDIUMCVSS 5.4EG 5.42026-03-28
The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged operations. An attacker can install and acti…
- CVE-2025-15466MEDIUMCVSS 5.4EG 5.42026-01-20
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes i…
- CVE-2025-15473MEDIUMCVSS 4.3EG 4.32026-03-12
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.
- CVE-2025-15475MEDIUMCVSS 5.3EG 5.32026-01-14
The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3…
- CVE-2025-15476MEDIUMCVSS 4.3EG 4.32026-02-07
The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bucketlister_do_admin_ajax() function in all versions up to, and including, 0.1.5. This makes it possible…
- CVE-2025-15507MEDIUMCVSS 5.3EG 5.32026-02-04
The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it poss…
- CVE-2025-15510MEDIUMCVSS 5.3EG 5.32026-01-31
The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possi…
- CVE-2025-15511MEDIUMCVSS 5.3EG 5.32026-01-28
The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_webhook() function in all versions up to, and including, 2.0.0. This makes it possible for unauthentica…
- CVE-2025-15512MEDIUMCVSS 5.3EG 5.32026-01-14
The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.3. This makes it possib…
- CVE-2025-15516MEDIUMCVSS 4.3EG 4.32026-01-24
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for a…
- CVE-2025-15524MEDIUMCVSS 4.3EG 4.32026-02-11
The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for a…
- CVE-2025-15563MEDIUMCVSS 5.3EG 5.32026-02-19
Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.
- CVE-2025-15565MEDIUMCVSS 5.3EG 5.32026-04-14
The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated atta…
- CVE-2025-1557MEDIUMCVSS 4.3EG 4.32025-02-22
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been discl…
- CVE-2025-1562CRITICALCVSS 9.8EG 9.82025-06-18
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_a…
- CVE-2025-15634MEDIUMCVSS 4.3EG 4.32026-05-09
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
- CVE-2025-1639HIGHCVSS 8.8EG 8.82025-03-04
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and includi…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →