Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2025-05-30 CVE-2025-4597 The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12.
network
low complexity
CWE-862
6.5
2025-05-27 CVE-2025-5117 The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6.
network
low complexity
CWE-862
8.8
2025-05-27 CVE-2025-4683 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5.
network
low complexity
CWE-862
4.3
2025-05-26 CVE-2025-5185 A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1.
network
low complexity
CWE-862
4.3
2025-05-21 CVE-2025-4105 The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'splitIt-flexfields-payment-gateway.php' file in all versions up to, and including, 4.2.8.
network
low complexity
CWE-862
5.4
2025-05-19 CVE-2025-39412 Missing Authorization vulnerability in Averta Master Slider
Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.
network
low complexity
averta CWE-862
4.3
2025-05-19 CVE-2025-4477 The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API.
network
low complexity
CWE-862
7.2
2025-05-18 CVE-2025-4887 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0.
network
low complexity
CWE-862
4.3
2025-05-17 CVE-2025-3527 The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6.
network
low complexity
CWE-862
6.4
2025-05-16 CVE-2025-48138 Missing Authorization vulnerability in Bertha AI
Missing Authorization vulnerability in berthaai BERTHA AI allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
bertha CWE-862
8.8