VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 268 of 473
  • CVE-2025-41012MedDec 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in…

  • CVE-2025-13441MedNov 27, 2025
    risk 0.34cvss 5.3epss 0.00

    The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for…

  • CVE-2025-12579MedNov 27, 2025
    risk 0.34cvss 5.3epss 0.00

    The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to reset the plugin's settings.

  • CVE-2025-13414MedNov 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdash_watch_for_export() function in all versions up to, and including, 3.3.11. This makes it possible for unauthenticated attackers…

  • CVE-2025-13404MedNov 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the duplicate_post() function in all versions up to, and including, 1.2.20. This makes it possible for authenticated attackers, with…

  • CVE-2025-13386MedNov 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'options_update' function in all versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to delete the…

  • CVE-2025-12043MedNov 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for…

  • CVE-2025-13318MedNov 22, 2025
    risk 0.34cvss 5.3epss 0.00

    The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it…

  • CVE-2025-13317MedNov 22, 2025
    risk 0.34cvss 5.3epss 0.00

    The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts…

  • CVE-2025-66114MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations as Single Products Woocommerce:…

  • CVE-2025-66113MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Chat Support for Messenger: from n/a through <= 1.2.18.

  • CVE-2025-66110MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tiktok Feed: from n/a through <= 1.0.23.

  • CVE-2025-66107MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through…

  • CVE-2025-66099MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.

  • CVE-2025-66086MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.

  • CVE-2025-66083MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

  • CVE-2025-66082MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

  • CVE-2025-66077MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.

  • CVE-2025-66071MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Order Numbers for WooCommerce: from n/a through <=…

  • CVE-2025-66060MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.