VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 193 of 241
  • CVE-2026-58066CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity…

  • CVE-2026-15240HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any…

  • CVE-2026-14305MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the…

  • CVE-2026-63238MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.

  • CVE-2026-14300HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.00

    The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers…

  • CVE-2026-13690HigJul 29, 2026
    risk 0.00cvss 7.4epss 0.00

    The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

  • CVE-2026-64745LowJul 27, 2026
    risk 0.00cvss 2.4epss 0.00

    This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.

  • CVE-2026-43766MedJul 27, 2026
    risk 0.00cvss 4.6epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2026-66014HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

  • CVE-2026-9830HigJul 27, 2026
    risk 0.00cvss 8.2epss 0.00

    The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data…

  • CVE-2026-14568MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete…

  • CVE-2026-13597CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for…

  • CVE-2026-13332CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including…

  • CVE-2026-12493HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated…

  • CVE-2026-12255HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication…

  • CVE-2026-12504HigJul 24, 2026
    risk 0.00cvss epss 0.00

    Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an…

  • CVE-2026-12877CriJul 24, 2026
    risk 0.00cvss 9.1epss 0.00

    The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project…

  • CVE-2026-56191CriJul 24, 2026
    risk 0.00cvss 10.0epss 0.01

    Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-15981CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's…

  • CVE-2026-10697HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.