VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 277 of 327
  • CVE-2026-16736HigAug 5, 2026
    risk 0.00cvss 7.5epss 0.00

    The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open…

  • CVE-2026-15230HigAug 5, 2026
    risk 0.00cvss 8.1epss 0.00

    The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon…

  • CVE-2026-16547MedAug 4, 2026
    risk 0.00cvss 5.9epss 0.00

    The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged…

  • CVE-2026-16295MedAug 4, 2026
    risk 0.00cvss 4.3epss 0.00

    The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces,…

  • CVE-2026-14848MedAug 4, 2026
    risk 0.00cvss 5.4epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another…

  • CVE-2026-14816MedAug 4, 2026
    risk 0.00cvss 6.5epss 0.00

    The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email…

  • CVE-2026-12698MedAug 4, 2026
    risk 0.00cvss 4.3epss 0.00

    The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile,…

  • CVE-2026-15430MedAug 3, 2026
    risk 0.00cvss 6.2epss 0.00

    Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and…

  • CVE-2026-16563MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons,…

  • CVE-2026-15241HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and,…

  • CVE-2026-15151HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin…

  • CVE-2026-14315MedAug 1, 2026
    risk 0.00cvss 6.5epss 0.00

    The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs…

  • CVE-2026-13329MedAug 1, 2026
    risk 0.00cvss 6.5epss 0.00

    The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured…

  • CVE-2026-12966MedAug 1, 2026
    risk 0.00cvss 5.3epss 0.00

    The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers…

  • CVE-2026-52134CriJul 31, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

  • CVE-2026-65311MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service…

  • CVE-2026-14834MedJul 31, 2026
    risk 0.00cvss 6.5epss 0.00

    The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses…

  • CVE-2026-66803CriJul 30, 2026
    risk 0.00cvss 10.0epss 0.00

    Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58043HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem…

  • CVE-2026-15250MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and…