VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,492)

page 154 of 275
  • CVE-2024-33941MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.

  • CVE-2023-25457MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slider: from n/a through 1.5.1.

  • CVE-2024-3601MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated…

  • CVE-2024-2109MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2024-2043MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for…

  • CVE-2024-1584MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1.…

  • CVE-2024-0629MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to…

  • CVE-2024-33587MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0.

  • CVE-2024-33586MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.

  • CVE-2024-33596MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.

  • CVE-2024-33652MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.

  • CVE-2024-32826MedApr 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Vektor,Inc. VK Block Patterns.This issue affects VK Block Patterns: from n/a through 1.31.0.

  • CVE-2024-32678MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5.

  • CVE-2024-32677MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.

  • CVE-2023-32127MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.

  • CVE-2023-25785MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Shoaib Saleem WP Post Rating allows Functionality Misuse.This issue affects WP Post Rating: from n/a through 2.5.

  • CVE-2024-32679MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16.

  • CVE-2024-32691MedApr 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.

  • CVE-2024-32684MedApr 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

  • CVE-2024-32601MedApr 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Popup Anything.This issue affects Popup Anything: from n/a through 2.8.