CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,985 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 161 of 180
- CVE-2026-35662MEDIUMCVSS 4.3EG 4.32026-04-10
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their authorized scope. Attackers can exploit this by using the send action to com…
- CVE-2026-3567MEDIUMCVSS 5.3EG 5.32026-03-21
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to…
- CVE-2026-3569MEDIUMCVSS 5.3EG 5.32026-04-24
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally…
- CVE-2026-3570MEDIUMCVSS 5.3EG 5.32026-03-21
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global s…
- CVE-2026-3571MEDIUMCVSS 6.5EG 6.52026-04-04
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and includin…
- CVE-2026-3581MEDIUMCVSS 5.3EG 5.32026-04-16
The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This mak…
- CVE-2026-3582MEDIUMCVSS 4.3EG 4.32026-03-10
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve issues and commits from private and intern…
- CVE-2026-3595MEDIUMCVSS 5.3EG 5.32026-04-16
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/…
- CVE-2026-3596CRITICALCVSS 9.8EG 9.82026-04-16
The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the in…
- CVE-2026-3601MEDIUMCVSS 4.3EG 4.32026-05-05
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it p…
- CVE-2026-3614HIGHCVSS 8.8EG 8.82026-04-16
The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router` AJAX handler. This makes it possible fo…
- CVE-2026-3637MEDIUMCVSS 4.3EG 4.32026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their…
- CVE-2026-3638MEDIUMCVSS 5.9EG 5.92026-03-09
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.
- CVE-2026-3640MEDIUMCVSS 5.3EG 5.32026-06-19
The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_ca…
- CVE-2026-3642MEDIUMCVSS 5.3EG 5.32026-04-15
The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or n…
- CVE-2026-3645MEDIUMCVSS 5.3EG 5.32026-03-21
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_config() function, which handles the 'punnel_save_config' AJAX action, lacks any capabili…
- CVE-2026-3646MEDIUMCVSS 5.3EG 5.32026-04-08
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization…
- CVE-2026-3649MEDIUMCVSS 5.3EG 5.32026-04-15
The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_short…
- CVE-2026-3651MEDIUMCVSS 5.3EG 5.32026-03-21
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_…
- CVE-2026-3770HIGHCVSS 8.8EG 8.82026-03-08
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been p…
- CVE-2026-3829MEDIUMCVSS 5.4EG 5.42026-05-14
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' func…
- CVE-2026-3831MEDIUMCVSS 4.3EG 4.32026-04-01
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. …
- CVE-2026-38329CRITICALCVSS 9.8EG 9.82026-06-15
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker …
- CVE-2026-3895MEDIUMCVSS 6.4EG 6.42026-05-27
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insuff…
- CVE-2026-3896MEDIUMCVSS 6.4EG 6.42026-05-27
The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input …
- CVE-2026-3897MEDIUMCVSS 6.4EG 6.42026-05-27
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient…
- CVE-2026-3906MEDIUMCVSS 4.3EG 4.32026-03-11
WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor.…
- CVE-2026-39348MEDIUMCVSS 4.3EG 4.32026-04-07
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attachment download handlers, allowing authenticated low-privilege users to re…
- CVE-2026-39351CRITICALCVSS 9.1EG 9.12026-04-07
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
- CVE-2026-39355HIGHCVSS 8.8EG 8.82026-04-07
Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This…
- CVE-2026-39360MEDIUMCVSS 4.3EG 4.32026-04-07
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket c…
- CVE-2026-39386HIGHCVSS 8.8EG 8.82026-04-21
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (me…
- CVE-2026-39397CRITICALCVSS 9.8EG 9.82026-04-07
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAcce…
- CVE-2026-39401MEDIUMCVSS 5.4EG 5.42026-04-07
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored c…
- CVE-2026-39429CRITICALCVSS 9.1EG 9.12026-04-08
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization …
- CVE-2026-39432HIGHCVSS 8.2EG 8.22026-05-12
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.
- CVE-2026-39433MEDIUMCVSS 6.5EG 6.52026-06-17
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
- CVE-2026-39448HIGHCVSS 7.5EG 7.52026-07-02
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
- CVE-2026-39476MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.
- CVE-2026-39477MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3.
- CVE-2026-39485MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
- CVE-2026-39488MEDIUMCVSS 6.5EG 6.52026-04-08
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
- CVE-2026-39490HIGHCVSS 7.5EG 7.52026-06-16
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
- CVE-2026-39501MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.
- CVE-2026-39503HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
- CVE-2026-39504MEDIUMCVSS 5.4EG 5.42026-04-08
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5.
- CVE-2026-39505MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a th…
- CVE-2026-39506MEDIUMCVSS 4.3EG 4.32026-04-08
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.
- CVE-2026-39509MEDIUMCVSS 5.3EG 5.32026-04-08
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.
- CVE-2026-39513HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →