Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-22302 Missing Authorization vulnerability in WP Grids WP Wand ai-content-generation allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-01-07 MEDIUM 6.4 CVE-2024-56294 Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002025-01-07 HIGH 8.8 CVE-2024-56276 Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Secur… Wpforms 1.9.2.3+ Fix from $1,9502025-01-07 MEDIUM 5.3 CVE-2024-51651 Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002025-01-07 CRITICAL 9.8 CVE-2024-56273 Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly … Migration\, Backup\, Staging 0.9.107+ Fix from $2,3002025-01-07 HIGH 8.8 CVE-2024-12202 The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabi… Mitigation only Fix from $1,9502025-01-07 MEDIUM 5.3 CVE-2024-10866 The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_… Mitigation only Fix from $1,6002025-01-07 HIGH 8.8 CVE-2024-11725 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… Sms Alert Order Notifications 3.7.7+ Fix from $1,9502025-01-07 MEDIUM 5.3 CVE-2024-9697 The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… Social Rocket after 1.3.4 Fix from $1,6002025-01-07 HIGH 8.6 CVE-2024-12535 The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' fu… Mitigation only Fix from $1,9502025-01-07 MEDIUM 5.3 CVE-2024-12158 The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing … Mitigation only Fix from $1,6002025-01-07 MEDIUM 5.3 CVE-2024-12176 The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_… Mitigation only Fix from $1,6002025-01-07 MEDIUM 6.5 CVE-2024-11496 The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_… Infility Global 2.9.9+ Fix from $1,6002025-01-07 MEDIUM 5.3 CVE-2024-12559 The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_a… Mitigation only Fix from $1,6002025-01-07 MEDIUM 5.3 CVE-2024-55408 An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafte… Mitigation only Fix from $1,6002025-01-06 MEDIUM 5.9 CVE-2025-22385 An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require … Configured Commerce 5.2.2408+ Fix from $1,6002025-01-04 MEDIUM 5.4 CVE-2023-23672 Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1. Givewp 2.25.2+ Fix from $1,6002025-01-02 MEDIUM 5.4 CVE-2022-45811 Missing Authorization vulnerability in WeyHan Ng Post Teaser.This issue affects Post Teaser: from n/a through 4.1.5. No fix yet Fix from $1,6002025-01-02 MEDIUM 5.3 CVE-2022-47601 Missing Authorization vulnerability in JoomUnited WP Table Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002025-01-02 MEDIUM 5.3 CVE-2023-48739 Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Co… Mitigation only Fix from $1,6002025-01-02 HIGH 7.1 CVE-2023-48758 Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,9502025-01-02 MEDIUM 6.5 CVE-2023-40327 Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from … Mitigation only Fix from $1,6002025-01-02 MEDIUM 6.5 CVE-2023-45633 Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect… Mitigation only Fix from $1,6002025-01-02 CRITICAL 9.8 CVE-2022-45830 Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3. Analytify Google Analytics Dashboard 4.3.0+ Fix from $2,3002025-01-02 MEDIUM 5.4 CVE-2023-32240 Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo… Mitigation only Fix from $1,6002025-01-02 HIGH 8.8 CVE-2024-56266 Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Accessing Funct… Mp3 Audio Player For Music\, Radio \& Podcast 5.9+ Fix from $1,9502025-01-02 MEDIUM 5.4 CVE-2024-56253 Missing Authorization vulnerability in supsystic Data Tables Generator by Supsystic data-tables-generator-by-supsystic allows Exploiting Incorrectly … Mitigation only Fix from $1,6002025-01-02 MEDIUM 5.3 CVE-2024-56238 Missing Authorization vulnerability in QuantumCloud Floating Action Buttons floating-action-buttons allows Accessing Functionality Not Properly Const… Mitigation only Fix from $1,6002025-01-02 MEDIUM 5.4 CVE-2024-56244 Missing Authorization vulnerability in WP Royal Ashe Extra ashe-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-01-02 HIGH 7.5 CVE-2023-47648 Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,9502025-01-02