The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handle…
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a mis…
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in vers…
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to au…
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulti…
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allo…
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauth…
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS…
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may b…
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted in…
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi…
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes an…
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mo…
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipul…
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, f…