VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 5 of 32
  • CVE-2025-8359CriSep 6, 2025
    risk 0.64cvss 9.8epss 0.00

    The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as…

  • CVE-2025-54738CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a through <= 4.7.9.

  • CVE-2025-54725CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.

  • CVE-2025-34520CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can…

  • CVE-2025-5821CriAug 23, 2025
    risk 0.64cvss 9.8epss 0.01

    The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging in a user with the data that was previously verified through the facebook_ajax_login_callback() function.…

  • CVE-2025-7642CriAug 23, 2025
    risk 0.64cvss 9.8epss 0.00

    The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This…

  • CVE-2025-50904CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

  • CVE-2025-27129CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.

  • CVE-2025-54713CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0.

  • CVE-2025-8995CriAug 15, 2025
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.

  • CVE-2025-51452CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.00

    In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

  • CVE-2025-53187CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function…

  • CVE-2025-7710CriAug 2, 2025
    risk 0.64cvss 9.8epss 0.01

    The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for…

  • CVE-2025-7444CriJul 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log…

  • CVE-2025-30026CriJul 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

  • CVE-2025-51381CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an attacker may bypass the authentication of the product from within the LAN to which the product is connected.

  • CVE-2025-4973CriJun 12, 2025
    risk 0.64cvss 9.8epss 0.00

    The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when…

  • CVE-2025-30184CriJun 9, 2025
    risk 0.64cvss 9.8epss 0.00

    CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

  • CVE-2025-31022CriJun 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authentication Abuse.This issue affects PayU India: from n/a through < 3.8.8.

  • CVE-2025-4797CriJun 3, 2025
    risk 0.64cvss 9.8epss 0.00

    The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie.…