VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 238 of 475
  • CVE-2020-36729MedJun 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for…

  • CVE-2019-25143MedJun 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset…

  • CVE-2023-2415MedJun 3, 2023
    risk 0.35cvss 5.4epss 0.01

    The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for…

  • CVE-2023-3053MedJun 3, 2023
    risk 0.35cvss 5.4epss 0.01

    The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with…

  • CVE-2023-2547MedMay 31, 2023
    risk 0.35cvss 5.4epss 0.00

    The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with…

  • CVE-2023-33948MedMay 24, 2023
    risk 0.35cvss 5.3epss 0.01

    The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.

  • CVE-2023-1868MedApr 5, 2023
    risk 0.35cvss 6.5epss 0.01

    The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to…

  • CVE-2020-36667MedMar 7, 2023
    risk 0.35cvss 5.4epss 0.00

    The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and…

  • CVE-2023-25768MedFeb 15, 2023
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.

  • CVE-2023-0720MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

  • CVE-2023-0717MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0716MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0715MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0711MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0684MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

  • CVE-2023-0718MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0719MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

  • CVE-2023-0712MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-0713MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2022-3482MedJan 26, 2023
    risk 0.35cvss 5.3epss 0.01

    An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only