VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,490)

page 239 of 275
  • CVE-2024-9109MedOct 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.12. This makes it possible for…

  • CVE-2024-8667MedOct 24, 2024
    risk 0.21cvss 4.3epss 0.00

    The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This…

  • CVE-2024-9891MedOct 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This…

  • CVE-2024-9824MedOct 12, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. This makes it possible…

  • CVE-2024-8431MedOct 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated…

  • CVE-2024-8675MedOct 1, 2024
    risk 0.21cvss 4.3epss 0.00

    The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-7030MedAug 21, 2024
    risk 0.21cvss 4.3epss 0.00

    The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2024-5997MedJul 18, 2024
    risk 0.21cvss 4.3epss 0.00

    The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_user and duplicate_post functions in all versions up to, and including, 0.6. This makes it…

  • CVE-2024-5703MedJul 17, 2024
    risk 0.21cvss 4.3epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible…

  • CVE-2024-6465MedJul 13, 2024
    risk 0.21cvss 4.3epss 0.00

    The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with…

  • CVE-2024-5704MedJul 9, 2024
    risk 0.21cvss 4.3epss 0.00

    The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. ffw_insert_new_faq, ffw_hide_discount_notice, ffw_delete_all_faqs,…

  • CVE-2024-6012MedJul 2, 2024
    risk 0.21cvss 4.3epss 0.00

    The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for…

  • CVE-2024-5864MedJun 28, 2024
    risk 0.21cvss 4.3epss 0.00

    The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-3249MedJun 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_xml_data, xml_data_import, import_option_data, import_widgets, and import_customizer_settings functions in all versions up to,…

  • CVE-2023-3352MedJun 21, 2024
    risk 0.21cvss 4.3epss 0.00

    The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the…

  • CVE-2024-3602MedJun 20, 2024
    risk 0.21cvss 4.3epss 0.00

    The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the disconnect_promolayer function in all versions up to, and…

  • CVE-2024-5858MedJun 15, 2024
    risk 0.21cvss 4.3epss 0.00

    The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for authenticated attackers,…

  • CVE-2024-35168MedJun 11, 2024
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.

  • CVE-2024-4468MedJun 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes it possible for authenticated attackers…

  • CVE-2024-4661MedJun 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and…