VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 27 of 464
  • CVE-2025-27270CriMar 3, 2025
    risk 0.57cvss 9.8epss 0.00

    Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Privilege Escalation.This issue affects Residential Address Detection: from n/a through <= 2.5.4.

  • CVE-2024-9195HigFeb 28, 2025
    risk 0.57cvss 8.8epss 0.00

    The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the update_settings case in the /admin/ajax.php file in all versions up to, and including,…

  • CVE-2025-1682HigFeb 28, 2025
    risk 0.57cvss 8.8epss 0.01

    The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify…

  • CVE-2024-13677HigFeb 18, 2025
    risk 0.57cvss 8.8epss 0.01

    The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27. This is due to the plugin not properly validating a user's identity prior to…

  • CVE-2025-26378HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.

  • CVE-2025-26375HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrary privileges via crafted HTTP requests.

  • CVE-2025-26371HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups via crafted HTTP requests.

  • CVE-2025-26369HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to user groups via crafted HTTP requests.

  • CVE-2024-12296HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.4. This makes it possible for…

  • CVE-2024-13653HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' functions in all versions up to, and…

  • CVE-2024-13643HigFeb 11, 2025
    risk 0.57cvss 8.8epss 0.01

    The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privilege escalation and denial of service conditions due to missing capability checks on the backup_options() and…

  • CVE-2024-13343HigFeb 1, 2025
    risk 0.57cvss 8.8epss 0.00

    The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-12821HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.00

    The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the upm_upload_media() function in all versions up to, and including, 3.12.0. This makes it possible…

  • CVE-2024-12129HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.00

    The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'royal_restore_backup' function in all versions up to, and including, 2.9.2. This makes it possible for…

  • CVE-2025-24734HigJan 27, 2025
    risk 0.57cvss 8.8epss 0.01

    Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affects Better Find and Replace: from n/a through <= 1.6.7.

  • CVE-2024-11936HigJan 26, 2025
    risk 0.57cvss 8.8epss 0.00

    The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible…

  • CVE-2024-12848HigJan 9, 2025
    risk 0.57cvss 8.8epss 0.01

    The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' function in all versions up to, and including, 4.6. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2024-11816HigJan 8, 2025
    risk 0.57cvss 8.8epss 0.01

    The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers, with…

  • CVE-2024-12202HigJan 7, 2025
    risk 0.57cvss 8.8epss 0.01

    The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'ironMusic_ajax' function in all versions up to, and including, 3.6. This makes it possible for authenticated…

  • CVE-2023-47179HigJan 2, 2025
    risk 0.57cvss 8.8epss 0.01

    Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6.