VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,392)

page 179 of 270
  • CVE-2025-10732MedOct 14, 2025
    risk 0.28cvss 4.3epss 0.00

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings…

  • CVE-2025-8682MedOct 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the…

  • CVE-2025-11442MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the component API Endpoint. The manipulation results in cross-site request forgery. The attack may be performed from remote. The exploit has been released to the…

  • CVE-2025-11439MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit has been made public and…

  • CVE-2025-9029MedOct 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the…

  • CVE-2025-9194MedOct 3, 2025
    risk 0.28cvss 4.3epss 0.00

    The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clean() function in all versions up to, and including, 1.6.5. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2025-11029MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.…

  • CVE-2025-60166MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms PRO: from n/a through <= 2.0.5.

  • CVE-2025-60165MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in HaruTheme Frames frames allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frames: from n/a through <= 1.5.7.

  • CVE-2025-60159MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.

  • CVE-2025-60152MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5.

  • CVE-2025-60148MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Download: from n/a through <= 2.0.9.

  • CVE-2025-60143MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.69.

  • CVE-2025-60128MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Delisho: from n/a through <= 1.1.3.

  • CVE-2025-60123MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.3.

  • CVE-2025-60122MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.4.

  • CVE-2025-60094MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stackable: from n/a through <= 3.18.1.

  • CVE-2025-59591MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.33.

  • CVE-2025-59561MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4.

  • CVE-2025-59559MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payrexx Payment Gateway for WooCommerce: from n/a through <= 3.1.5.