CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 149 of 173
- CVE-2026-25386MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2.
- CVE-2026-25387MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1…
- CVE-2026-25388MEDIUMCVSS 5.4EG 5.42026-02-19
Missing Authorization vulnerability in scripteo Ads Pro ap-plugin-scripteo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads Pro: from n/a through <= 5.0.
- CVE-2026-25390MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.3.
- CVE-2026-25391MEDIUMCVSS 5.4EG 5.42026-02-19
Missing Authorization vulnerability in WP Grids WP Wand ai-content-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through <= 1.3.07.
- CVE-2026-25393MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6.
- CVE-2026-25394MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6.
- CVE-2026-25395MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in ikreatethemes Business Roy business-roy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Roy: from n/a through <= 1.1.4.
- CVE-2026-25396HIGHCVSS 7.5EG 7.52026-03-25
Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooComme…
- CVE-2026-25398MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vertex Addons for Elementor: from n/a t…
- CVE-2026-25399MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in CryoutCreations Serious Slider cryout-serious-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serious Slider: from n/a through <= 1.2.7.
- CVE-2026-25401HIGHCVSS 7.5EG 7.52026-03-25
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.
- CVE-2026-25402MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for …
- CVE-2026-25404MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n/a through <= 2.4.0.
- CVE-2026-25407MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n/a through <= 4.6.4.
- CVE-2026-25408MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Notifier: from n/a through <= 1.3.5.
- CVE-2026-25409MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in crgeary JAMstack Deployments wp-jamstack-deployments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JAMstack Deployments: from n/a through <= 1.1.1.
- CVE-2026-25410MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in tstephenson WP-CORS wp-cors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CORS: from n/a through <= 0.2.2.
- CVE-2026-25415MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18.
- CVE-2026-25416MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <…
- CVE-2026-25419MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.5.
- CVE-2026-25420MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.
- CVE-2026-25423LOWCVSS 3.8EG 3.82026-02-19
Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.
- CVE-2026-25425HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
- CVE-2026-25426MEDIUMCVSS 5.3EG 5.32026-05-26
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through…
- CVE-2026-25430MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integra…
- CVE-2026-25431MEDIUMCVSS 5.3EG 5.32026-05-12
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
- CVE-2026-25436MEDIUMCVSS 5.3EG 5.32026-05-07
Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.
- CVE-2026-25437MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GZSEO: from n/a through <= 2.0.14.
- CVE-2026-25440MEDIUMCVSS 5.3EG 5.32026-06-15
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
- CVE-2026-25441MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21.
- CVE-2026-25443HIGHCVSS 7.5EG 7.52026-03-19
Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
- CVE-2026-25444MEDIUMCVSS 4.3EG 4.32026-05-26
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
- CVE-2026-25454MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through <= 4.4.1.
- CVE-2026-25455MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n…
- CVE-2026-25456HIGHCVSS 7.3EG 7.52026-03-25
Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automated FedEx live/…
- CVE-2026-25459MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in uixthemes Sober sober allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sober: from n/a through <= 3.5.12.
- CVE-2026-25460MEDIUMCVSS 6.3EG 6.32026-03-25
Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ave Core: from n/a through <= 2.9.1.
- CVE-2026-25462MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects avalex: from n/a through <= 3.1.3.
- CVE-2026-25469MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through…
- CVE-2026-25473MEDIUMCVSS 5.4EG 5.42026-02-19
Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.
- CVE-2026-25517LOWCVSS 2.7EG 2.72026-02-04
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge o…
- CVE-2026-25531MEDIUMCVSS 4.3EG 4.32026-02-13
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projec…
- CVE-2026-25538HIGHCVSS 8.8EG 8.82026-02-04
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to ob…
- CVE-2026-2559MEDIUMCVSS 5.3EG 5.32026-03-18
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the fun…
- CVE-2026-25609MEDIUMCVSS 5.4EG 5.42026-02-10
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.
- CVE-2026-25633MEDIUMCVSS 4.3EG 4.32026-02-11
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without perm…
- CVE-2026-25714MEDIUMCVSS 4.3EG 4.32026-06-16
Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
- CVE-2026-25742MEDIUMCVSS 5.3EG 5.32026-04-03
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS_E…
- CVE-2026-25752CRITICALCVSS 9.1EG 9.12026-02-06
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →