VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 173 of 475
  • CVE-2024-7888MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to,…

  • CVE-2024-7858MedAug 30, 2024
    risk 0.41cvss 6.3epss 0.00

    The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-33005MedAug 13, 2024
    risk 0.41cvss 6.3epss 0.00

    Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on…

  • CVE-2024-41624MedJul 29, 2024
    risk 0.41cvss 6.3epss 0.00

    Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact.

  • CVE-2023-48761MedJun 19, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

  • CVE-2024-38506MedJun 18, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

  • CVE-2023-36694MedJun 14, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.

  • CVE-2024-34826MedJun 11, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler.This issue affects CF7 WOW Styler: from n/a through <= 1.6.4.

  • CVE-2024-31307MedJun 9, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.

  • CVE-2024-5087MedJun 8, 2024
    risk 0.41cvss 6.3epss 0.00

    The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it…

  • CVE-2024-31281MedMay 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.

  • CVE-2023-31234MedMay 7, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Tilda Publishing.This issue affects Tilda Publishing: from n/a through 0.3.23.

  • CVE-2024-33923MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.

  • CVE-2024-3942MedMay 2, 2024
    risk 0.41cvss 6.3epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it…

  • CVE-2024-1677MedMay 2, 2024
    risk 0.41cvss 6.3epss 0.01

    The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all…

  • CVE-2023-32295MedApr 11, 2024
    risk 0.41cvss 6.3epss 0.01

    Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.

  • CVE-2024-1850MedApr 9, 2024
    risk 0.41cvss 6.3epss 0.01

    The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion of posts due to a missing capability check on functions hooked by AJAX actions in all versions up to, and including, 3.3. This makes it possible for…

  • CVE-2022-44626MedMar 25, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.

  • CVE-2024-24739MedFeb 13, 2024
    risk 0.41cvss 6.3epss 0.00

    SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact on confidentiality, integrity and availability of the application.

  • CVE-2022-40203MedJan 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.