VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,492)

page 143 of 275
  • CVE-2024-13423MedMar 5, 2025
    risk 0.34cvss 5.3epss 0.00

    The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for…

  • CVE-2024-8682MedMar 5, 2025
    risk 0.34cvss 5.3epss 0.00

    The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating…

  • CVE-2025-1502MedMar 1, 2025
    risk 0.34cvss 5.3epss 0.00

    The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in all versions up to, and including, 1.33.3. This makes it possible for unauthenticated…

  • CVE-2025-1249MedFeb 26, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through <= 6.6.4.1.

  • CVE-2025-26975MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3.

  • CVE-2024-13719MedFeb 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…

  • CVE-2025-27013MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7.

  • CVE-2025-22291MedFeb 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide…

  • CVE-2025-23187MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

  • CVE-2024-11133MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to download event…

  • CVE-2025-22686MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from n/a through <= 5.0.17.

  • CVE-2025-24747MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0.

  • CVE-2025-24662MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.

  • CVE-2025-24600MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5.

  • CVE-2025-24590MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in picu picu picu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects picu: from n/a through <= 2.4.0.

  • CVE-2025-24705MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Quick View: from n/a through <= 1.1.1.

  • CVE-2025-24633MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0.

  • CVE-2025-24596MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Table Lite: from n/a through <= 3.8.7.

  • CVE-2024-12104MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This…

  • CVE-2025-23862MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot contact-form-7-anti-spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through <= 1.0.1.