CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,616 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 141 of 173
- CVE-2026-11818MEDIUMCVSS 5.4EG 5.42026-07-10
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a us…
- CVE-2026-11852MEDIUMCVSS 6.5EG 6.52026-06-10
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no perm…
- CVE-2026-11858HIGHCVSS 8.4EG 8.42026-06-17
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe without sufficient acces…
- CVE-2026-11868MEDIUMCVSS 5.3EG 5.32026-07-20
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
- CVE-2026-11876MEDIUMCVSS 5.0EG 5.02026-07-21
In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenant…
- CVE-2026-11909LOWCVSS 3.3EG 9.82026-07-10
Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
- CVE-2026-11912HIGHCVSS 7.5EG 7.52026-06-20
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and…
- CVE-2026-11990MEDIUMCVSS 5.3EG 5.32026-07-10
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to…
- CVE-2026-11992MEDIUMCVSS 4.3EG 4.32026-07-10
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it …
- CVE-2026-12093MEDIUMCVSS 5.3EG 5.32026-06-18
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it po…
- CVE-2026-12094MEDIUMCVSS 5.3EG 5.32026-06-24
The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler i…
- CVE-2026-12097MEDIUMCVSS 5.3EG 5.32026-07-08
The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possib…
- CVE-2026-12103MEDIUMCVSS 4.3EG 4.32026-07-11
The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes …
- CVE-2026-12105MEDIUMCVSS 6.5EG 6.52026-06-16
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.
- CVE-2026-12113MEDIUMCVSS 4.3EG 4.32026-07-01
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, …
- CVE-2026-12119MEDIUMCVSS 6.5EG 6.52026-06-20
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for a…
- CVE-2026-12122MEDIUMCVSS 5.3EG 5.32026-07-02
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unaut…
- CVE-2026-12133MEDIUMCVSS 4.3EG 4.32026-07-01
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check…
- CVE-2026-12134MEDIUMCVSS 4.3EG 4.32026-07-02
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is au…
- CVE-2026-12153CRITICALCVSS 9.8EG 9.82026-07-08
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…
- CVE-2026-12238MEDIUMCVSS 5.3EG 5.32026-06-19
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an a…
- CVE-2026-12349MEDIUMCVSS 5.3EG 5.32026-06-30
The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_side…
- CVE-2026-1239HIGHCVSS 7.5EG 7.52026-07-01
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions …
- CVE-2026-12404MEDIUMCVSS 5.3EG 5.32026-06-27
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to per…
- CVE-2026-12406MEDIUMCVSS 5.3EG 5.32026-07-09
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not p…
- CVE-2026-12407HIGHCVSS 8.8EG 8.82026-06-18
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce v…
- CVE-2026-12411CRITICALCVSS 9.6EG 9.62026-06-26
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security…
- CVE-2026-12428MEDIUMCVSS 6.5EG 6.52026-07-09
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and …
- CVE-2026-12432MEDIUMCVSS 5.3EG 5.32026-06-27
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_…
- CVE-2026-12434MEDIUMCVSS 4.3EG 4.32026-07-16
The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level a…
- CVE-2026-12435MEDIUMCVSS 4.3EG 4.32026-07-01
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized…
- CVE-2026-12471MEDIUMCVSS 4.3EG 4.32026-06-27
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Sub…
- CVE-2026-12472MEDIUMCVSS 5.3EG 5.32026-07-02
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is auth…
- CVE-2026-12515MEDIUMCVSS 4.3EG 4.32026-06-17
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for rep…
- CVE-2026-1253MEDIUMCVSS 4.3EG 5.32026-03-21
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'atomchat_update_auth_ajax' and 'atomchat_update_layout_ajax' functions in all version…
- CVE-2026-1254MEDIUMCVSS 4.3EG 4.32026-02-14
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to …
- CVE-2026-12557MEDIUMCVSS 5.3EG 5.32026-07-03
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This m…
- CVE-2026-12593HIGHCVSS 8.7EG 8.72026-07-09
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Pre…
- CVE-2026-12694CRITICALCVSS 9.1EG 9.12026-07-17
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
- CVE-2026-12715HIGHCVSS 8.5EG 8.52026-07-17
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing request…
- CVE-2026-12723MEDIUMCVSS 5.3EG 5.32026-07-20
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under …
- CVE-2026-12729MEDIUMCVSS 4.3EG 4.32026-07-03
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration(…
- CVE-2026-12738MEDIUMCVSS 4.3EG 4.32026-07-11
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is author…
- CVE-2026-1280HIGHCVSS 7.5EG 7.52026-01-28
The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for…
- CVE-2026-12902MEDIUMCVSS 4.3EG 4.32026-07-01
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is author…
- CVE-2026-12907LOWCVSS 2.7EG 2.72026-07-16
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, fo…
- CVE-2026-12955MEDIUMCVSS 4.3EG 4.32026-07-10
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc…
- CVE-2026-12973MEDIUMCVSS 6.5EG 6.52026-07-20
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitra…
- CVE-2026-1298MEDIUMCVSS 4.3EG 5.32026-01-28
The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.5.2. This is due to missing capability checks on the `image_replacement_from_url` function that is hooked to the `er…
- CVE-2026-12988MEDIUMCVSS 6.4EG 6.42026-07-14
The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verifi…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →