VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,492)

page 153 of 275
  • CVE-2024-32727MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Rometheme RomethemeForm For Elementor.This issue affects RomethemeForm For Elementor: from n/a through 1.1.2.

  • CVE-2024-32820MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2.

  • CVE-2024-32814MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.1.

  • CVE-2024-32813MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9.

  • CVE-2024-32779MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Avirtum Vision Interactive.This issue affects Vision Interactive: from n/a through 1.7.1.

  • CVE-2024-35659MedJun 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.

  • CVE-2024-1175MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated…

  • CVE-2024-35174MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.

  • CVE-2024-32802MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.

  • CVE-2023-34186MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.

  • CVE-2022-45070MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.

  • CVE-2024-3915MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.00

    The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update…

  • CVE-2024-32719MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

  • CVE-2024-30459MedMay 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.

  • CVE-2024-33908MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.

  • CVE-2024-33907MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.26.2.

  • CVE-2024-34372MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.

  • CVE-2024-33910MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

  • CVE-2024-33929MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

  • CVE-2024-33920MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.