VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 247 of 475
  • CVE-2026-18436MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign//restore-revision/<revision_id>). The route in the vulnerable range was…

  • CVE-2026-14317MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator…

  • CVE-2026-13692MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.

  • CVE-2026-54004MedJul 9, 2026
    risk 0.34cvss epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access…

  • CVE-2026-7492MedJul 8, 2026
    risk 0.34cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper…

  • CVE-2026-9175MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This is due to the get_single_account() REST API callback being registered with a permission_callback that…

  • CVE-2026-9172MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on the delete_single_account() function in versions up to, and including, 1.2.0. The REST route…

  • CVE-2026-8690MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-8617MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and…

  • CVE-2026-7617MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2026-12094MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both…

  • CVE-2026-7859MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

  • CVE-2026-56213MedJun 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for any app_id. Attackers can exploit this by…

  • CVE-2026-6798MedJun 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-10034MedJun 19, 2026
    risk 0.34cvss 5.3epss 0.01

    The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-12093MedJun 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2026-10029MedJun 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract…

  • CVE-2026-8383MedJun 17, 2026
    risk 0.34cvss 5.3epss 0.08

    The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and…

  • CVE-2024-33909MedJun 17, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

  • CVE-2026-9187MedJun 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered…