Vulnerabilities (CVE)

Filtered by CWE-862
Total 9018 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2945 1 Open-emr 1 Openemr 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2869 1 Butlerblog 1 Wp-members 2026-06-17 N/A 4.3 MEDIUM
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.
CVE-2023-2791 1 Mattermost 1 Mattermost 2026-06-17 N/A 4.3 MEDIUM
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
CVE-2023-2787 1 Mattermost 1 Mattermost 2026-06-17 N/A 6.5 MEDIUM
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.
CVE-2023-2786 1 Mattermost 1 Mattermost 2026-06-17 N/A 4.3 MEDIUM
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.
CVE-2023-2784 1 Mattermost 1 Mattermost 2026-06-17 N/A 4.2 MEDIUM
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
CVE-2023-2783 1 Mattermost 1 Mattermost 2026-06-17 N/A 4.3 MEDIUM
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
CVE-2023-2764 1 Nsqua 1 Draw Attention 2026-06-17 N/A 4.3 MEDIUM
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the featured image of arbitrary posts with an image that exists in the media library.
CVE-2023-2757 1 Plugin 1 Waiting 2026-06-17 N/A 7.4 HIGH
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to access functions to save plugin data that can potentially lead to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-2716 1 Groundhogg 1 Groundhogg 2026-06-17 N/A 5.4 MEDIUM
The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ajax_upload_file' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload a file to the contact, and then lists all the other uploaded files related to the contact.
CVE-2023-2715 1 Groundhogg 1 Groundhogg 2026-06-17 N/A 4.3 MEDIUM
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that sends the website's data to the plugin developer, and it is also possible to create an admin access with an auto login link that is also sent to the plugin developer with the ticket. It only works if the plugin is activated with a valid license.
CVE-2023-2714 1 Groundhogg 1 Groundhogg 2026-06-17 N/A 4.3 MEDIUM
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.
CVE-2023-2590 1 Answer 1 Answer 2026-06-17 N/A 3.5 LOW
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.
CVE-2023-2562 1 Gallery-metabox Project 1 Gallery-metabox 2026-06-17 N/A 4.3 MEDIUM
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
CVE-2023-2561 1 Gallery-metabox Project 1 Gallery-metabox 2026-06-17 N/A 4.3 MEDIUM
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
CVE-2023-2557 1 Pluginus 1 Wordpress Currency Switcher Professional 2026-06-17 N/A 4.3 MEDIUM
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit an arbitrary custom drop-down currency switcher.
CVE-2023-2556 1 Pluginus 1 Wordpress Currency Switcher 2026-06-17 N/A 4.3 MEDIUM
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete an arbitrary custom drop-down currency switcher.
CVE-2023-2555 1 Pluginus 1 Wordpress Currency Switcher Professional 2026-06-17 N/A 4.3 MEDIUM
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create a custom drop-down currency switcher.
CVE-2023-2547 1 Featherplugins 1 Feather Login Page 2026-06-17 N/A 5.4 MEDIUM
The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the temp user generated by the plugin.
CVE-2023-2545 1 Featherplugins 1 Feather Login Page 2026-06-17 N/A 8.1 HIGH
The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to access the login links, which can be used for privilege escalation.