VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 25 of 464
  • CVE-2025-49723HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

  • CVE-2025-5953HigJul 4, 2025
    risk 0.57cvss 8.8epss 0.00

    The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions 2.0.0 through 2.2.17. The AJAX handler reads the client-supplied $_POST['role'] and,…

  • CVE-2025-52824HigJun 27, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile DJ Manager: from n/a through <= 1.7.8.3.

  • CVE-2025-1562CriJun 18, 2025
    risk 0.57cvss 9.8epss 0.03

    The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_plugins() function and a…

  • CVE-2025-42982HigJun 10, 2025
    risk 0.57cvss 8.8epss 0.00

    SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.

  • CVE-2025-5894HigJun 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create administrator accounts, and subsequently log into the system using those accounts.

  • CVE-2025-47601HigJun 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0.

  • CVE-2025-49288HigJun 6, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This issue affects Ultimate WP Mail: from n/a through <= 1.3.5.

  • CVE-2025-5701HigJun 5, 2025
    risk 0.57cvss 8.8epss 0.02

    The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for…

  • CVE-2025-48998HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been…

  • CVE-2025-47690HigMay 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1.

  • CVE-2025-3876HigMay 10, 2025
    risk 0.57cvss 8.8epss 0.00

    The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for…

  • CVE-2025-28202HigMay 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.

  • CVE-2025-1304HigMay 1, 2025
    risk 0.57cvss 8.8epss 0.01

    The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with…

  • CVE-2025-46557CriApr 30, 2025
    risk 0.57cvss 9.8epss 0.01

    XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page…

  • CVE-2025-3906HigApr 26, 2025
    risk 0.57cvss 8.8epss 0.00

    The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wep_opcoes' function in all versions up to, and including, 1.7.5. This makes it possible for authenticated attackers, with…

  • CVE-2025-1279HigApr 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it…

  • CVE-2025-3604CriApr 24, 2025
    risk 0.57cvss 9.8epss 0.01

    The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible…

  • CVE-2025-3058HigApr 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for…

  • CVE-2025-39533HigApr 17, 2025
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects Starfish Review Generation & Marketing: from n/a through <= 3.1.19.