VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,496)

page 124 of 275
  • CVE-2025-14978MedJan 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all versions up…

  • CVE-2025-14078MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback function…

  • CVE-2025-14029MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve…

  • CVE-2025-12825MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.01

    The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to…

  • CVE-2025-14463MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results…

  • CVE-2025-12895MedJan 15, 2026
    risk 0.34cvss 5.3epss 0.00

    The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the kalium_vc_contact_form_request() function in all versions up to, and including, 3.29. This makes it possible for…

  • CVE-2025-15512MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to set…

  • CVE-2025-15475MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for…

  • CVE-2025-14173MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the `logout` function called via the `actions` function hooked to `admin_init`. This makes it possible…

  • CVE-2025-14948MedJan 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes…

  • CVE-2025-13717MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf_check_download_request' function in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers…

  • CVE-2025-14146MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default…

  • CVE-2025-14886MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any…

  • CVE-2026-22488MedJan 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <=…

  • CVE-2026-22486MedJan 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Gallery: from n/a through 1.18.9.

  • CVE-2026-0676MedJan 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zorka: from n/a through <= 1.5.7.

  • CVE-2025-13496MedJan 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_landings_auth_get function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with…

  • CVE-2025-13419MedJan 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bfe/v1/revert' REST API endpoint in all versions up to, and including, 5.0.0.…

  • CVE-2025-69364MedJan 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.

  • CVE-2025-69359MedJan 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.