VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 99 of 115
  • CVE-2026-15260MedAug 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying…

  • CVE-2026-15231LowAug 3, 2026
    risk 0.00cvss 2.7epss 0.00

    The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts…

  • CVE-2026-16291MedAug 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

  • CVE-2026-8155MedJul 31, 2026
    risk 0.00cvss 5.4epss 0.00

    The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

  • CVE-2026-15209MedJul 31, 2026
    risk 0.00cvss 6.5epss 0.00

    The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

  • CVE-2026-14927LowJul 31, 2026
    risk 0.00cvss 3.7epss 0.00

    The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer…

  • CVE-2026-14847MedJul 31, 2026
    risk 0.00cvss 4.3epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by…

  • CVE-2026-14843MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing…

  • CVE-2026-12697MedJul 31, 2026
    risk 0.00cvss 5.4epss 0.00

    The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

  • CVE-2026-12376MedJul 31, 2026
    risk 0.00cvss 4.3epss 0.00

    The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site,…

  • CVE-2026-10700MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks,…

  • CVE-2026-12945HigJul 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

  • CVE-2026-15658HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.

  • CVE-2026-67348HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including…

  • CVE-2026-15257MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated…

  • CVE-2026-15255MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form…

  • CVE-2026-14310MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to…

  • CVE-2026-13345MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft,…

  • CVE-2026-13178HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

  • CVE-2026-13145MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an…