CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,990 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 174 of 180
- CVE-2026-57323MEDIUMCVSS 5.8EG 5.82026-06-26
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
- CVE-2026-57324MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
- CVE-2026-57327MEDIUMCVSS 6.3EG 6.32026-06-29
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
- CVE-2026-57332HIGHCVSS 7.1EG 7.12026-06-29
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
- CVE-2026-57334MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- CVE-2026-57335MEDIUMCVSS 6.5EG 6.52026-06-29
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
- CVE-2026-57339MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
- CVE-2026-57340MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
- CVE-2026-57353MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
- CVE-2026-57355MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
- CVE-2026-57367HIGHCVSS 7.1EG 7.12026-07-23
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
- CVE-2026-57375MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.
- CVE-2026-57377MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.
- CVE-2026-57378HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.
- CVE-2026-57390MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Prod…
- CVE-2026-57392MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
- CVE-2026-57395MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
- CVE-2026-57400MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager f…
- CVE-2026-57404MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manag…
- CVE-2026-57405HIGHCVSS 7.1EG 7.12026-07-13
Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.
- CVE-2026-57406MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
- CVE-2026-57408MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.…
- CVE-2026-57412MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouchers: from n/a through <= 4.6.9.
- CVE-2026-57418MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a th…
- CVE-2026-57419MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce…
- CVE-2026-57424MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n…
- CVE-2026-57425MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
- CVE-2026-57429MEDIUMCVSS 6.5EG 6.52026-06-25
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
- CVE-2026-57430MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
- CVE-2026-57494HIGHCVSS 7.1EG 7.12026-06-18
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target a…
- CVE-2026-57498CRITICALCVSS 9.6EG 9.62026-06-29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any oper…
- CVE-2026-57518HIGHCVSS 8.8EG 8.82026-06-26
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization…
- CVE-2026-57520HIGHCVSS 7.1EG 7.12026-06-25
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in…
- CVE-2026-57521MEDIUMCVSS 4.3EG 4.32026-06-25
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpo…
- CVE-2026-5753MEDIUMCVSS 6.5EG 6.52026-05-06
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_sched…
- CVE-2026-57619MEDIUMCVSS 6.5EG 6.52026-06-25
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
- CVE-2026-57622MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
- CVE-2026-57632MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
- CVE-2026-57640MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
- CVE-2026-57645HIGHCVSS 8.1EG 8.12026-06-26
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
- CVE-2026-57648MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
- CVE-2026-57649MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
- CVE-2026-57654MEDIUMCVSS 6.5EG 6.52026-06-26
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
- CVE-2026-57660MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
- CVE-2026-57661MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
- CVE-2026-57669MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
- CVE-2026-57685MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
- CVE-2026-57688HIGHCVSS 8.2EG 8.22026-07-02
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
- CVE-2026-57689MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
- CVE-2026-57703MEDIUMCVSS 6.3EG 6.32026-07-23
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →