VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 248 of 475
  • CVE-2026-6964MedJun 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-25440MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

  • CVE-2026-50244MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the…

  • CVE-2026-4986MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

  • CVE-2026-8502MedJun 6, 2026
    risk 0.34cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'return_type' parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2026-40571MedJun 2, 2026
    risk 0.34cvss epss 0.00

    NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add…

  • CVE-2026-35443MedJun 2, 2026
    risk 0.34cvss epss 0.00

    NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where…

  • CVE-2025-53302MedJun 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5.

  • CVE-2026-46337MedMay 29, 2026
    risk 0.34cvss 5.3epss 0.00

    WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal serving wrappers gate behind…

  • CVE-2026-49053MedMay 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

  • CVE-2026-9014MedMay 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions up to, and including, 1.3. The function is hooked to both the wp_ajax_wpp-reset_stats and…

  • CVE-2026-25426MedMay 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

  • CVE-2026-24590MedMay 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

  • CVE-2026-39655MedMay 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

  • CVE-2026-27398MedMay 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.

  • CVE-2026-27357MedMay 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.

  • CVE-2026-24592MedMay 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.

  • CVE-2026-24546MedMay 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.

  • CVE-2026-27393MedMay 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6.

  • CVE-2025-15369MedMay 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated…