Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2023-25035

Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 5.3
CVE-2023-25048

Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2024-12-09
Spectra HIGH 8.8
CVE-2023-23825

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Fix: 2.3.1+
Fix from $1,950 2024-12-09
Spectra CRITICAL 9.8
CVE-2023-23834

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Fix: 2.3.1+
Fix from $2,300 2024-12-09
Unclassified MEDIUM 5.4
CVE-2023-23868

Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 5.4
CVE-2023-23886

Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 5.3
CVE-2023-23887

Missing Authorization vulnerability in Shaon Easy Google Analytics for WordPress allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 5.3
CVE-2023-23893

Missing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2024-12-09
Wp Time Slots Booking Form HIGH 7.2
CVE-2023-23895

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.…

Fix: 1.1.83+
Fix from $1,950 2024-12-09
Ebook Store CRITICAL 9.8
CVE-2023-22701

Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Fix: after 5.775
Fix from $2,300 2024-12-09
Jobboardwp HIGH 8.8
CVE-2023-23715

Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Con…

Fix: after 1.2.2
Fix from $1,950 2024-12-09
Jfinalcms HIGH 8.8
CVE-2024-12349

A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fi…

No fix yet
Fix from $1,950 2024-12-09
Wegia HIGH 7.5
CVE-2024-53473

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

Patch available
Fix from $1,950 2024-12-07
Unclassified MEDIUM 5.4
CVE-2024-12253

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing ca…

Mitigation only
Fix from $1,600 2024-12-07
Unclassified MEDIUM 5.3
CVE-2024-7894

The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing capability check on the 'act…

Mitigation only
Fix from $1,600 2024-12-07
Unclassified MEDIUM 5.3
CVE-2024-53826

Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPCas…

Mitigation only
Fix from $1,600 2024-12-06
Filebird HIGH 7.2
CVE-2024-53825

Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Fix: after 6.3.2
Fix from $1,950 2024-12-06
Unclassified CRITICAL 9.1
CVE-2024-53810

Missing Authorization vulnerability in N-Media Simple User Registration wp-registration allows Accessing Functionality Not Properly Constrained by AC…

Mitigation only
Fix from $2,300 2024-12-06
Unclassified MEDIUM 6.5
CVE-2024-53813

Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2024-12-06
Wp Mailster HIGH 8.8
CVE-2024-53803

Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Fix: 1.8.17+
Fix from $1,950 2024-12-06
Wp Mailster CRITICAL 9.8
CVE-2024-53805

Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Fix: 1.8.17+
Fix from $2,300 2024-12-06
Unclassified MEDIUM 5.4
CVE-2024-53806

Missing Authorization vulnerability in yonifre Maspik – Spam blacklist contact-forms-anti-spam allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2024-12-06
Unclassified MEDIUM 5.3
CVE-2024-53795

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Accessing Functionality Not Properly Constrained by ACLs.This issu…

Mitigation only
Fix from $1,600 2024-12-06
Unclassified CRITICAL 9.8
CVE-2024-12155

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca…

Mitigation only
Fix from $2,300 2024-12-06
Ultimate Coming Soon \& Maintenance MEDIUM 5.3
CVE-2024-9706

The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…

Fix: 1.1.0+
Fix from $1,600 2024-12-06
Unclassified MEDIUM 5.3
CVE-2024-12028

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions…

Mitigation only
Fix from $1,600 2024-12-06
Unclassified HIGH 8.8
CVE-2024-11323

The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missi…

Mitigation only
Fix from $1,950 2024-12-06
Cyberpanel MEDIUM 6.5
CVE-2024-54679

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Fix: after 2.3.7
Fix from $1,600 2024-12-05
Unclassified HIGH 8.8
CVE-2024-11643

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Mitigation only
Fix from $1,950 2024-12-04
Youtrack MEDIUM 5.3
CVE-2024-54155

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Fix: 2024.3.51866+
Fix from $1,600 2024-12-04