Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-10637

The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plug…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified MEDIUM 5.3
CVE-2025-11269

The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNo…

Patch available
Fix from $1,600 2025-10-25
Tutor Lms MEDIUM 5.3
CVE-2025-11564

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

Fix: 3.9.0+
Fix from $1,600 2025-10-25
Unclassified MEDIUM 5.3
CVE-2025-10694

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified MEDIUM 5.3
CVE-2025-10579

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Mitigation only
Fix from $1,600 2025-10-25
Unclassified HIGH 8.7
CVE-2025-62714

Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, ther…

Patch available
Fix from $1,950 2025-10-24
Unclassified MEDIUM 5.3
CVE-2025-12134

The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unau…

Mitigation only
Fix from $1,600 2025-10-24
App Connect Enterprise HIGH 8.8
CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actio…

Fix: after 13.0.4.2
Fix from $1,950 2025-10-24
Unclassified MEDIUM 5.4
CVE-2025-10749

The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and incl…

Mitigation only
Fix from $1,600 2025-10-24
Digital Experience Platform MEDIUM 5.3
CVE-2025-62256

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA th…

Fix: 7.4.3.110+
Fix from $1,600 2025-10-23
Unclassified HIGH 8.7
CVE-2025-62614

BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an authentication bypass vulner…

Patch available
Fix from $1,950 2025-10-22
Digital Experience Platform MEDIUM 6.5
CVE-2025-62247

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 20…

Fix: 2024.q1.20+
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-62027

Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3.

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-62048

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-62019

Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom.This issue affects Recipe Car…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified HIGH 7.5
CVE-2025-62022

Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.

Mitigation only
Fix from $1,950 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-62006

Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-53424

Missing Authorization vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows Exploiting Incorrectly Configure…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-53421

Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.3
CVE-2025-53236

Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-52757

Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-52738

Missing Authorization vulnerability in Wikimedia Foundation Wikipedia Preview wikipedia-preview allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-49961

Missing Authorization vulnerability in Breeze Team Breeze Checkout breeze-checkout allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-49949

Missing Authorization vulnerability in templazee Templazee templazee allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified HIGH 7.2
CVE-2025-49950

Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official In…

Mitigation only
Fix from $1,950 2025-10-22
Wordpress Learning Management System HIGH 7.5
CVE-2025-49925

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec…

Fix: 1.9.9.8+
Fix from $1,950 2025-10-22
Unclassified MEDIUM 5.3
CVE-2025-49913

Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Configured Access Control Security…

No fix yet
Fix from $1,600 2025-10-22
Unclassified HIGH 8.6
CVE-2025-49916

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-49920

Missing Authorization vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Exploiting Incorrectly Configured Access Control Sec…

No fix yet
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.3
CVE-2025-49899

Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Mitigation only
Fix from $1,600 2025-10-22