← Back
CWE-862

8,735 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,735)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ad Inserter Project
1Ad Inserter
Jun 17, 2026
Oct 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sen...Show more
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths.Show less
1Gvectors
1Wpdiscuz
Jun 17, 2026
Oct 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unaut...Show more
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post.Show less
1Gvectors
1Wpdiscuz
Jun 17, 2026
Oct 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for...Show more
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment.Show less
1Miniorange
1Google Authenticator
Jun 17, 2026
Oct 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it poss...Show more
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.Show less
1Adenion
1Blog2social
Jun 17, 2026
Oct 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-l...Show more
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.Show less
1Yanco
1Woocommerce Ean Payment Gateway
Jun 17, 2026
Oct 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes...Show more
The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update EAN numbers for orders.Show less
1Pluginus
1Bear Woocommerce Bulk Editor And Products Manager Professional
Jun 17, 2026
Oct 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible f...Show more
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.Show less
1Rightpress
1Woocommerce Dynamic Pricing & Discounts
Jun 17, 2026
Oct 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function w...Show more
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers to export the plugin's settings.Show less
1Cleantalk
1Security & Malware Scan
Jun 17, 2026
Oct 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and no...Show more
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to call functions and delete and/or upload files.Show less
1Ixpdata
1Easyinstall
Jun 17, 2026
Oct 19, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.
1Igorfuna
1Ad Inserter
Jun 17, 2026
Oct 19, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as...Show more
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, available roles, the plugin license key provided the remote debugging option is enabled. In the default state it is disabled.Show less
1Pluginus
1Bear Woocommerce Bulk Editor And Products Manager Professional
Jun 17, 2026
Oct 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This make...Show more
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.Show less
1E Gov
1E Gov
Jun 17, 2026
Oct 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A cra...Show more
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.Show less
1Sap
1S/4hana
Jun 17, 2026
Oct 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integ...Show more
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application. Show less
1Janusintl
2Noke Hd Smart Padlock Firmware
Noke Standard Smart Padlock Firmware
Jun 17, 2026
Oct 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.
1Acronis
1Agent
Jun 17, 2026
Oct 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16...Show more
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.Show less
1Sick
1Apu0200 Firmware
Jun 17, 2026
Oct 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.
1Mattermost
1Mattermost Server
Jun 17, 2026
Oct 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.
1Mediawiki
1Mediawiki
Jun 17, 2026
Oct 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo...Show more
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.Show less
1Google
1Android
Jun 17, 2026
Oct 8, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed