VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 245 of 475
  • CVE-2026-75798MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the…

  • CVE-2026-14550MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the…

  • CVE-2026-13406MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to…

  • CVE-2026-13172MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords…

  • CVE-2026-79104MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79044MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17587MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-10627MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-78291MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

  • CVE-2026-78258MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

  • CVE-2026-75027MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2026-16962MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated…

  • CVE-2026-55095MedAug 20, 2026
    risk 0.34cvss epss 0.00

    OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw…

  • CVE-2026-64965MedAug 20, 2026
    risk 0.34cvss epss 0.00

    ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the…

  • CVE-2026-17153MedAug 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-76340MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability…

  • CVE-2026-62670MedAug 19, 2026
    risk 0.34cvss 6.3epss 0.00

    Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits…

  • CVE-2026-18779MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.

  • CVE-2026-18777MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.

  • CVE-2026-47721MedAug 18, 2026
    risk 0.34cvss 6.3epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin…