CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
5,115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 90 of 103
- CVE-2026-12795HIGHCVSS 7.3EG 7.32026-06-21
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing aut…
- CVE-2026-12877CRITICALCVSS 9.1EG 9.12026-07-24
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This…
- CVE-2026-1305MEDIUMCVSS 5.3EG 5.32026-02-27
The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a flawed permission check in the `paidy_webhook_permission_check` function that uncondition…
- CVE-2026-13208MEDIUMCVSS 6.5EG 6.52026-06-24
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection…
- CVE-2026-13332CRITICALCVSS 9.1EG 9.12026-07-27
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of a…
- CVE-2026-13543MEDIUMCVSS 5.6EG 5.62026-06-29
A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google OAuth Login. The manipulatio…
- CVE-2026-13546HIGHCVSS 7.3EG 7.32026-06-29
A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initia…
- CVE-2026-13597CRITICALCVSS 9.1EG 9.12026-07-27
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthentica…
- CVE-2026-13600HIGHCVSS 8.1EG 8.12026-08-10
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configur…
- CVE-2026-1368HIGHCVSS 7.5EG 7.52026-02-18
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve…
- CVE-2026-13690HIGHCVSS 7.4EG 7.42026-07-29
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and …
- CVE-2026-1410MEDIUMCVSS 6.4EG 6.42026-01-26
A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipulation results in missing authentication. An attack on the physical device is feasible. Th…
- CVE-2026-14182CRITICALCVSS 9.8EG 9.82026-08-13
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowin…
- CVE-2026-14205CRITICALCVSS 9.8EG 9.82026-08-07
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a comple…
- CVE-2026-14214LOWCVSS 2.7EG 2.72026-08-01
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stor…
- CVE-2026-14216MEDIUMCVSS 6.5EG 6.52026-08-26
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notification…
- CVE-2026-14291HIGHCVSS 7.5EG 7.52026-07-23
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete auth…
- CVE-2026-14300HIGHCVSS 8.1EG 8.12026-07-29
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued f…
- CVE-2026-14305MEDIUMCVSS 5.3EG 5.32026-07-30
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbit…
- CVE-2026-14309HIGHCVSS 8.1EG 8.12026-08-01
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbit…
- CVE-2026-14541HIGHCVSS 7.5EG 7.52026-07-31
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined…
- CVE-2026-14547MEDIUMCVSS 5.3EG 5.32026-08-06
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipient…
- CVE-2026-14557CRITICALCVSS 9.1EG 9.12026-08-03
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any veri…
- CVE-2026-14561MEDIUMCVSS 6.5EG 6.52026-08-01
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthen…
- CVE-2026-14568MEDIUMCVSS 6.5EG 6.52026-07-27
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated …
- CVE-2026-14596HIGHCVSS 8.8EG 8.82026-08-01
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-for…
- CVE-2026-14622HIGHCVSS 7.3EG 7.32026-07-04
A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipu…
- CVE-2026-14627MEDIUMCVSS 5.6EG 5.62026-07-04
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such ma…
- CVE-2026-14714MEDIUMCVSS 6.5EG 6.52026-07-05
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_toke…
- CVE-2026-14830HIGHCVSS 7.5EG 7.52026-07-31
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders wi…
- CVE-2026-14836HIGHCVSS 8.1EG 8.12026-08-01
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, cl…
- CVE-2026-14919CRITICALCVSS 9.8EG 9.82026-07-31
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attacker…
- CVE-2026-15038CRITICALCVSS 9.8EG 9.82026-08-09
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attac…
- CVE-2026-15087MEDIUMCVSS 5.9EG 5.92026-07-10
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
- CVE-2026-15089CRITICALCVSS 9.1EG 9.12026-07-10
Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
- CVE-2026-15192MEDIUMCVSS 6.5EG 6.52026-07-09
A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to …
- CVE-2026-15206HIGHCVSS 7.5EG 7.52026-08-02
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh…
- CVE-2026-15210CRITICALCVSS 9.1EG 9.12026-08-05
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a logi…
- CVE-2026-1524CRITICALCVSS 9.8EG 9.82026-03-11
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or …
- CVE-2026-15240HIGHCVSS 7.5EG 7.52026-07-30
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved a…
- CVE-2026-15303CRITICALCVSS 9.8EG 9.82026-08-15
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_w…
- CVE-2026-15315HIGHCVSS 8.7EG 8.72026-08-18
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authe…
- CVE-2026-15341CRITICALCVSS 9.8EG 9.82026-08-15
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore execute…
- CVE-2026-15348MEDIUMCVSS 6.3EG 6.32026-07-23
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hook…
- CVE-2026-15372HIGHCVSS 7.5EG 7.52026-08-05
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authenticati…
- CVE-2026-15384MEDIUMCVSS 5.7EG 5.72026-08-16
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level …
- CVE-2026-15459HIGHCVSS 8.1EG 8.12026-08-06
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key th…
- CVE-2026-15491HIGHCVSS 7.3EG 7.32026-07-12
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. Th…
- CVE-2026-15542HIGHCVSS 7.3EG 7.32026-07-13
A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack c…
- CVE-2026-15557HIGHCVSS 7.3EG 7.32026-07-13
A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →