VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-88802High· 7.5
2w ago

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a re…

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a re…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-81648Critical· 10.0PoC
2w ago

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

▾ AbyssalEPSS 0.50%via NVD
CVE-2026-74933High· 8.8
2w ago

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configurat…

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configurat…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-90545Medium· 4.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restrict…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restrict…

▾ TwilightWWBN · AVideoEPSS 0.29%via NVD
CVE-2026-90544Medium· 4.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts …

▾ SunlitWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-90537High· 8.2PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a…

▾ MidnightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-90535High· 7.5PoC
2w ago

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminat…

▾ Midnightflowiseai · flowiseEPSS 0.48%via NVD
CVE-2026-90533Medium· 6.5PoC
2w ago

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash an…

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash an…

▾ Twilightflowiseai · flowiseEPSS 0.34%via NVD
CVE-2026-11355Medium· 5.3
2w ago

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and d…

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and d…

▾ Sunlitdesignthemes · DT LMS – elearning, WordPress LMS PluginEPSS 0.24%via NVD
CVE-2026-90551Medium· 5.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API wi…

▾ SunlitWWBN · AVideoEPSS 0.40%via NVD
CVE-2026-90547Medium· 5.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protecte…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protecte…

▾ TwilightWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-90546Medium· 4.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Att…

▾ SunlitWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-90540Medium· 4.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos …

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-87919Medium· 4.9
2w ago

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-…

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-87797Medium· 4.3
2w ago

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber …

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber …

▾ SunlitEPSS 0.25%via NVD
CVE-2026-90454Medium· 5.3
2w ago

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, …

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, …

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-68535Medium· 4.3
2w ago

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-81916Medium· 4.3
2w ago

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to o…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-81915Medium· 5.3
2w ago

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEdi…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.29%via NVD
CVE-2026-18122Medium· 6.0
2w ago

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.23%via NVD
CVE-2026-27378Medium· 5.3
2w ago

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

▾ Sunlitmagepeopleteam · advanced-partial-payment-or-deposit-for-woocommerceEPSS 0.29%via NVD
CVE-2026-62089High· 7.1
2w ago

WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

▾ TwilightPixar Labs · master-addonsEPSS 0.32%via CVEORG
CVE-2026-62137Medium· 5.3
2w ago

WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.

▾ SunlitJohn James Jacoby · bbpressEPSS 0.31%via CVEORG
CVE-2026-62135Medium· 5.3
2w ago

WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.

▾ SunlitArraytics · bookticsEPSS 0.29%via CVEORG
CVE-2026-62132Medium· 5.3
2w ago

WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.

▾ Sunlitmasteriyo · learning-management-systemEPSS 0.29%via CVEORG
CVE-2026-11496Medium· 6.5
2w ago

Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure

The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX ha…

▾ Sunlitedgarrojas · PDF Builder for WooCommerce. Create invoices,packing slips and moreEPSS 0.26%via CVEORG
CVE-2024-12145Medium· 4.3
2w ago

BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion

The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes…

▾ Sunlitbuddypress · BuddyPressEPSS 0.19%via CVEORG
CVE-2026-89265Medium· 4.3PoC
2w ago

MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …

▾ Twilightmoxi624 · MoguBlogEPSS 0.37%via CVEORG
CVE-2026-62136Medium· 5.3
2w ago

WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.

▾ Sunlitwpdesk · flexible-quantity-measurement-price-calculator-for-woocommerceEPSS 0.29%via CVEORG
CVE-2026-62114Medium· 5.3
2w ago

WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.

▾ SunlitWP Chill · content-protectorEPSS 0.31%via CVEORG
CWE-862 vulnerabilities (CVEs) — page 15 · VulnSea