VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,494)

page 133 of 275
  • CVE-2025-12041MedOct 31, 2025
    risk 0.34cvss 5.3epss 0.00

    The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download files restricted…

  • CVE-2025-11191MedOct 31, 2025
    risk 0.34cvss 5.3epss 0.00

    The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

  • CVE-2025-64211MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4.

  • CVE-2025-64199MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WpEstate wpresidence wpresidence allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpresidence: from n/a through <= 5.3.2.

  • CVE-2025-58711MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8.

  • CVE-2025-62977MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in 沃之涛 百度站长SEO合集(支持百度/神马/Bing/头条推送) baiduseo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 百度站长SEO合集(支持百度/神马/Bing/头条推送): from n/a…

  • CVE-2025-62976MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sendle Shipping: from n/a through <= 6.02.

  • CVE-2025-62970MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Spencer Haws Link Whisper Free link-whisper allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through <= 0.9.2.

  • CVE-2025-62964MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.6.

  • CVE-2025-62946MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8.

  • CVE-2025-62944MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Mark O'Donnell MSTW CSV EXPORTER mstw-csv-exporter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSTW CSV EXPORTER: from n/a through <= 1.4.

  • CVE-2025-62922MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Shambhu Patnaik Export Categories export-categories allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export Categories: from n/a through <= 1.0.

  • CVE-2025-62892MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.

  • CVE-2025-62884MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.

  • CVE-2025-10579MedOct 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in all versions up to, and including, 5.5.0. This makes it possible for authenticated…

  • CVE-2025-49913MedOct 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoSchedule: from n/a through <= 3.4.0.

  • CVE-2025-49906MedOct 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPComplete: from n/a through <= 2.9.5.3.

  • CVE-2025-49903MedOct 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ZoloBlocks: from n/a through <= 2.3.11.

  • CVE-2025-49899MedOct 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Whydonate: from n/a through <= 4.0.15.

  • CVE-2025-49376MedOct 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects DELUCKS SEO: from n/a through <= 2.5.9.