VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,492)

page 140 of 275
  • CVE-2025-47486MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Plus: from n/a through <= 3.1.9.

  • CVE-2025-47485MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through <= 2.1.22.

  • CVE-2025-47457MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in dgamoni LocateAndFilter locateandfilter allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LocateAndFilter: from n/a through <= 1.6.16.

  • CVE-2025-47450MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.13.

  • CVE-2025-39367MedApr 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.

  • CVE-2025-46489MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1.

  • CVE-2025-46485MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.

  • CVE-2025-39390MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6.

  • CVE-2024-13307MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites'…

  • CVE-2025-46247MedApr 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

  • CVE-2025-46244MedApr 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3.

  • CVE-2025-39457MedApr 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8.

  • CVE-2025-39531MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in slazzercom Slazzer Background Changer slazzer-background-changer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Slazzer Background Changer: from n/a through <= 3.14.

  • CVE-2025-39513MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND activedemand allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ActiveDEMAND: from n/a through <= 0.2.46.

  • CVE-2025-32260MedApr 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.

  • CVE-2025-32259MedApr 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Alimir WP ULike wp-ulike.This issue affects WP ULike: from n/a through <= 4.7.9.1.

  • CVE-2025-26888MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through <= 5.3.8.

  • CVE-2025-31042MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sandwich Adsense: from n/a through <= 4.0.2.

  • CVE-2025-31012MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4.

  • CVE-2025-26657MedApr 8, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability.