CVE-2026-65469
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
CVSS
5.3
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-862
0.2%EPSS · 30 days0.3%
2026-08-102026-09-07
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-31747.5 HIG—
——0The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.4hCVE-2026-25205.4 MED—
——0The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update any plugin with a main file of 'main.php' to its latest version.4hCVE-2026-93317.1 HIG—
——0The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.4hCVE-2026-85400——
——0Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.7hCVE-2026-77132——
——0It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.7hCVE-2026-817907.5 HIG—
——0Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.4h