CVE-2026-39787 — Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
Cybersecurity watch: alerts, vulnerabilities, news and tools to protect yourself.
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.3.
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing …