VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 8 of 32
  • CVE-2024-9931CriOct 26, 2024
    risk 0.64cvss 9.8epss 0.01

    The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to…

  • CVE-2024-9930CriOct 26, 2024
    risk 0.64cvss 9.8epss 0.01

    The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing validation on the user being supplied in the 'verify_email' action. This makes it possible for unauthenticated attackers to…

  • CVE-2024-10381CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable…

  • CVE-2024-9488CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers…

  • CVE-2024-49604CriOct 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

  • CVE-2024-49328CriOct 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

  • CVE-2024-9893CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated…

  • CVE-2024-49247CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through <= 1.6.

  • CVE-2024-9105CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the 'ultimate_ai_register_or_login_with_google' function. This makes it possible for…

  • CVE-2024-9822CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user,…

  • CVE-2024-8943CriOct 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log…

  • CVE-2024-9289CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating…

  • CVE-2024-9106CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.02

    The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log…

  • CVE-2024-43692CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

  • CVE-2024-8277CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly…

  • CVE-2024-7503CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for…

  • CVE-2024-6684CriAug 12, 2024
    risk 0.64cvss epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not…

  • CVE-2024-7007CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

  • CVE-2024-38437CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

  • CVE-2024-5432CriJun 20, 2024
    risk 0.64cvss 9.8epss 0.01

    The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated…