Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-25336 Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25338 Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrect… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25348 Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25332 Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Acces… No fix yet Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25320 Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured A… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25321 Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25311 Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25315 Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23804 Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Co… No fix yet Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-24375 Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-24999 Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25000 Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-23543 Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly C… Mitigation only Fix from $1,6002026-02-19 MEDIUM 6.5 CVE-2026-23545 Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-02-19 HIGH 7.1 CVE-2026-23547 Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Ac… Mitigation only Fix from $1,9502026-02-19 MEDIUM 5.3 CVE-2026-23548 Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security L… No fix yet Fix from $1,6002026-02-19 HIGH 7.5 CVE-2026-23541 Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec… Mitigation only Fix from $1,9502026-02-19 MEDIUM 5.4 CVE-2026-2284 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.8. Thi… Mitigation only Fix from $1,6002026-02-19 CRITICAL 9.8 CVE-2026-25242 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global Re… Gogs 0.14.1+ Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-0974 The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin instal… Mitigation only Fix from $1,9502026-02-19 HIGH 7.2 CVE-2025-15041 The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… Mitigation only Fix from $1,9502026-02-19 MEDIUM 5.3 CVE-2025-14357 The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widg… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2025-13864 The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. T… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2025-13930 The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… Mitigation only Fix from $1,6002026-02-19 HIGH 8.8 CVE-2025-13603 The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to… Mitigation only Fix from $1,9502026-02-19 HIGH 7.2 CVE-2025-12975 The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing cap… Mitigation only Fix from $1,9502026-02-19 HIGH 8.8 CVE-2025-12845 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data t… Mitigation only Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2025-11725 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple fu… Mitigation only Fix from $1,6002026-02-19 HIGH 7.5 CVE-2025-11754 The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings'… Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-27181 MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() m… Majordomo Patch available Fix from $1,9502026-02-18