CWE-862
8,736 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,736)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog |
1Themehunk 1Contact Form & Lead Form Elementor Builder Jun 17, 2026 Jan 16, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various setting...Show more |
1Totolink 1N350rt Firmware Jun 17, 2026 Jan 16, 2024 6.9 MEDIUM· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improp...Show more |
1Totolink 1T8 Firmware Jun 17, 2026 Jan 16, 2024 5.3 MEDIUM· v4 9.1 CRITICAL· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation...Show more |
1Vmware 2Aria Automation Cloud FoundationJun 17, 2026 Jan 16, 2024 N/A· v4 8.3 HIGH· v3 N/A· v2 Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauthorized access to remote
organizations and workflows.
|
1Kishorkhambu 1Wp Custom Widget Area Jun 17, 2026 Jan 15, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create,...Show more |
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and le...Show more |
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitra...Show more |
1Demomentsomtres 1Export Posts With Images Jun 17, 2026 Jan 15, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the co...Show more |
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspa...Show more |
1Centralsquare 1Click2gov Building Permit Jun 17, 2026 Jan 12, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the us...Show more |
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
|
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all ver...Show more |
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jan 11, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly imp...Show more |
The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possibl...Show more |
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all ve...Show more |
The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 1.2.4. This...Show more |
1Daan 1Complete Analytics Optimization Suite Jun 17, 2026 Jan 11, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 4.7.1...Show more |
The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_set...Show more |