VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 69 of 82
  • CVE-2025-12367MedNov 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2025-10902MedOct 24, 2025
    risk 0.21cvss 4.3epss 0.00

    The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ai_scan_result_remove' function in all versions up to, and including, 1.0.15. This makes it possible for authenticated attackers, with…

  • CVE-2025-11510MedOct 18, 2025
    risk 0.21cvss 4.3epss 0.00

    The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes…

  • CVE-2025-8147MedAug 29, 2025
    risk 0.21cvss 4.3epss 0.00

    The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2025-7221MedAug 21, 2025
    risk 0.21cvss 4.3epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and including, 4.5.0. This makes it possible for…

  • CVE-2025-8401MedJul 31, 2025
    risk 0.21cvss 4.3epss 0.00

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and…

  • CVE-2025-27601MedMar 11, 2025
    risk 0.21cvss 4.3epss 0.00

    Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information…

  • CVE-2024-13552MedMar 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2025-24784MedJan 30, 2025
    risk 0.21cvss 4.3epss 0.00

    kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well constrained impact on cluster resources.…

  • CVE-2024-50701MedDec 30, 2024
    risk 0.21cvss 4.3epss 0.00

    TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.

  • CVE-2021-3991MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

  • CVE-2023-35022LowJun 30, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.

  • CVE-2024-1803MedMay 23, 2024
    risk 0.21cvss 4.3epss 0.00

    The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed…

  • CVE-2023-47037MedNov 12, 2023
    risk 0.21cvss 4.3epss 0.01

    We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting…

  • CVE-2023-3957MedJul 27, 2023
    risk 0.21cvss 4.3epss 0.01

    The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with…

  • CVE-2023-0583MedJun 3, 2023
    risk 0.21cvss 4.3epss 0.01

    The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings…

  • CVE-2022-40208MedMar 24, 2023
    risk 0.21cvss 4.3epss 0.01

    In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

  • CVE-2023-21452LowMar 16, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

  • CVE-2023-21436LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.

  • CVE-2023-0610MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.