CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 156 of 173
- CVE-2026-3651MEDIUMCVSS 5.3EG 5.32026-03-21
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_…
- CVE-2026-3829MEDIUMCVSS 5.4EG 5.42026-05-14
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' func…
- CVE-2026-3831MEDIUMCVSS 4.3EG 4.32026-04-01
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. …
- CVE-2026-38329CRITICALCVSS 9.8EG 9.82026-06-15
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker …
- CVE-2026-3895MEDIUMCVSS 6.4EG 6.42026-05-27
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insuff…
- CVE-2026-3896MEDIUMCVSS 6.4EG 6.42026-05-27
The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input …
- CVE-2026-3897MEDIUMCVSS 6.4EG 6.42026-05-27
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient…
- CVE-2026-3906MEDIUMCVSS 4.3EG 4.32026-03-11
WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor.…
- CVE-2026-39348MEDIUMCVSS 4.3EG 4.32026-04-07
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attachment download handlers, allowing authenticated low-privilege users to re…
- CVE-2026-39351CRITICALCVSS 9.1EG 9.12026-04-07
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
- CVE-2026-39355CRITICALCVSS 9.9EG 9.92026-04-07
Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This…
- CVE-2026-39360MEDIUMCVSS 4.3EG 4.32026-04-07
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket c…
- CVE-2026-39386HIGHCVSS 8.8EG 8.82026-04-21
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (me…
- CVE-2026-39397CRITICALCVSS 9.4EG 9.42026-04-07
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAcce…
- CVE-2026-39401MEDIUMCVSS 5.4EG 5.42026-04-07
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored c…
- CVE-2026-39429HIGHCVSS 8.2EG 8.22026-04-08
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization …
- CVE-2026-39432HIGHCVSS 8.2EG 8.22026-05-12
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.
- CVE-2026-39433MEDIUMCVSS 6.5EG 6.52026-06-17
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
- CVE-2026-39448HIGHCVSS 7.5EG 7.52026-07-02
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
- CVE-2026-39476MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.
- CVE-2026-39477MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3.
- CVE-2026-39485MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
- CVE-2026-39488MEDIUMCVSS 6.5EG 6.32026-04-08
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
- CVE-2026-39490HIGHCVSS 7.5EG 7.52026-06-16
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
- CVE-2026-39501MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.
- CVE-2026-39503HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
- CVE-2026-39504MEDIUMCVSS 5.4EG 5.42026-04-08
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5.
- CVE-2026-39505MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a th…
- CVE-2026-39506MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.
- CVE-2026-39509MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.
- CVE-2026-39513HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
- CVE-2026-39515MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Motors < 1.4.107 versions.
- CVE-2026-39520MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.
- CVE-2026-39524HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
- CVE-2026-39525MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
- CVE-2026-39528MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.
- CVE-2026-39533HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
- CVE-2026-39534HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
- CVE-2026-39535MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= …
- CVE-2026-39543MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.
- CVE-2026-39561MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.7.
- CVE-2026-39562MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a th…
- CVE-2026-39563MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.
- CVE-2026-39565MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7.
- CVE-2026-39569MEDIUMCVSS 6.5EG 6.52026-04-08
Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.
- CVE-2026-39584MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
- CVE-2026-39585MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in Arraytics Booktics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booktics: from n/a through 1.0.16.
- CVE-2026-39588MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Li…
- CVE-2026-39592MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Andy Ha DEPART depart-deposit-and-part-payment-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DEPART: from n/a through <= 1.0.7.
- CVE-2026-39593MEDIUMCVSS 6.5EG 6.52026-05-21
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.10.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →