VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 246 of 475
  • CVE-2026-8840MedAug 15, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-73403MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

  • CVE-2026-73401MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

  • CVE-2026-73353MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

  • CVE-2026-73349MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

  • CVE-2026-68753MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

  • CVE-2026-66377MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may access restricted repository information under specific conditions.

  • CVE-2026-18035MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.

  • CVE-2026-17021MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary…

  • CVE-2026-15237MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as…

  • CVE-2026-19350MedAug 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…

  • CVE-2026-16608MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.00

    The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and…

  • CVE-2026-48077MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any…

  • CVE-2026-66701MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

  • CVE-2026-32548MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

  • CVE-2026-11983MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the…

  • CVE-2026-16290MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group,…

  • CVE-2026-11995MedAug 1, 2026
    risk 0.34cvss 5.3epss 0.00

    The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized…

  • CVE-2026-15227MedJul 31, 2026
    risk 0.34cvss epss 0.00

    Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • CVE-2026-18437MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for…