Missing Authorization

CWE-862 · 39 records · 18 with a public proof-of-concept

Records the NVD classes as Missing Authorization (CWE-862), highest CVSS first.

  1. CRITICAL 9.3CVE-2026-15958

    The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and up

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-5581

    The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is regis

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.1CVE-2026-4431

    The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action be

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.8CVE-2026-8761

    The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-regi

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 8.8CVE-2026-70619public PoC

    Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 8.8CVE-2026-18650

    Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 8.8CVE-2026-17070

    Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 8.2CVE-2026-71264public PoC

    WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any u

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 8.2CVE-2026-71252public PoC

    toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 8.2CVE-2026-6627

    The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce ve

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 8.2CVE-2026-58080public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the defaul

    milo

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 8.1CVE-2026-7520

    The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 8.1CVE-2026-54418public PoC

    Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unli

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 8.1CVE-2026-70494public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to perm

    AI risk analysis on Exploit-DB.ai →

  15. HIGH 7.5CVE-2026-17613public PoC

    Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.

    AI risk analysis on Exploit-DB.ai →

  16. HIGH 7.5CVE-2026-7529

    The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all version

    AI risk analysis on Exploit-DB.ai →

  17. HIGH 7.5CVE-2026-6639

    The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being acces

    AI risk analysis on Exploit-DB.ai →

  18. HIGH 7.5CVE-2026-12000

    The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/w

    AI risk analysis on Exploit-DB.ai →

  19. HIGH 7.5CVE-2026-16561

    The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted

    AI risk analysis on Exploit-DB.ai →

  20. HIGH 7.3CVE-2026-6079

    The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for u

    AI risk analysis on Exploit-DB.ai →

  21. HIGH 7.2CVE-2026-16605

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other

    AI risk analysis on Exploit-DB.ai →

  22. MEDIUM 6.5CVE-2026-7456

    The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Su

    AI risk analysis on Exploit-DB.ai →

  23. MEDIUM 6.5CVE-2026-7726

    The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3.

    AI risk analysis on Exploit-DB.ai →

  24. MEDIUM 6.5CVE-2026-7753

    The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions u

    AI risk analysis on Exploit-DB.ai →

  25. MEDIUM 6.5CVE-2026-63248public PoC

    In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over Si

    milo

    AI risk analysis on Exploit-DB.ai →

  26. MEDIUM 5.4CVE-2026-70481public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrot

    AI risk analysis on Exploit-DB.ai →

  27. MEDIUM 5.3CVE-2026-70487public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any authenticate

    AI risk analysis on Exploit-DB.ai →

  28. MEDIUM 4.3CVE-2026-7105

    The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, w

    AI risk analysis on Exploit-DB.ai →

  29. MEDIUM 4.3CVE-2026-18819public PoC

    A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. Th

    AI risk analysis on Exploit-DB.ai →

  30. MEDIUM 4.3CVE-2026-70484public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permiss

    AI risk analysis on Exploit-DB.ai →

  31. MEDIUM 4.3CVE-2026-16546

    The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber t

    AI risk analysis on Exploit-DB.ai →

  32. MEDIUM 4.3CVE-2026-16056

    The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

    AI risk analysis on Exploit-DB.ai →

  33. MEDIUM 4.3CVE-2026-16035

    The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arb

    AI risk analysis on Exploit-DB.ai →

  34. LOW 3.1CVE-2026-70483public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who kn

    AI risk analysis on Exploit-DB.ai →

  35. UNSCOREDCVE-2026-13227public PoC

    An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, b

    AI risk analysis on Exploit-DB.ai →

  36. UNSCOREDCVE-2026-70475public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other exe

    AI risk analysis on Exploit-DB.ai →

  37. UNSCOREDCVE-2026-70473public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or work

    AI risk analysis on Exploit-DB.ai →

  38. UNSCOREDCVE-2026-13229public PoC

    Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

    AI risk analysis on Exploit-DB.ai →

  39. UNSCOREDCVE-2026-69252public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authentica

    AI risk analysis on Exploit-DB.ai →