VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 109 of 464
  • CVE-2024-9096HigMar 20, 2025
    risk 0.46cvss 7.1epss 0.01

    In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route lacks proper access control, such as middleware to ensure that only authorized users (e.g., project owners or admins) can modify…

  • CVE-2024-2292HigMar 20, 2025
    risk 0.46cvss 7.1epss 0.00

    Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.

  • CVE-2025-24654HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.

  • CVE-2025-24692HigFeb 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in M.Code Bulk Menu Edit bulk-menu-edit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Menu Edit: from n/a through <= 1.3.

  • CVE-2025-26372HigFeb 12, 2025
    risk 0.46cvss 7.1epss 0.00

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from groups via crafted HTTP requests.

  • CVE-2025-26370HigFeb 12, 2025
    risk 0.46cvss 7.1epss 0.00

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges from user groups via crafted HTTP requests.

  • CVE-2025-23982HigJan 27, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affects Fare Calculator: from n/a through <= 1.1.

  • CVE-2024-11848HigJan 15, 2025
    risk 0.46cvss 8.1epss 0.01

    The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with…

  • CVE-2023-48758HigJan 2, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.2.4.

  • CVE-2023-46632HigJan 2, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in David Cramer My Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Shortcodes: from n/a through 2.3.

  • CVE-2024-54381HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <= 3.1.1.

  • CVE-2024-54256HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.01

    Missing Authorization vulnerability in Seerox Easy Blocks pro easy-blocks-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Easy Blocks pro: from n/a through <= 1.0.21.

  • CVE-2023-51355HigDec 9, 2024
    risk 0.46cvss 8.2epss 0.01

    Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through <= 4.0.23.

  • CVE-2024-47314HigNov 1, 2024
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8.

  • CVE-2024-38721HigNov 1, 2024
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.5.0.

  • CVE-2024-44156HigOct 28, 2024
    risk 0.46cvss 7.1epss 0.00

    A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to bypass Privacy preferences.

  • CVE-2023-7294HigOct 16, 2024
    risk 0.46cvss 7.1epss 0.00

    The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers…

  • CVE-2023-7291HigOct 16, 2024
    risk 0.46cvss 7.1epss 0.00

    The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated…

  • CVE-2024-45732HigOct 14, 2024
    risk 0.46cvss 7.1epss 0.00

    In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the…

  • CVE-2024-5784HigAug 30, 2024
    risk 0.46cvss 7.1epss 0.00

    The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it…