VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 274 of 473
  • CVE-2025-4370MedJul 29, 2025
    risk 0.34cvss 5.3epss 0.00

    The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. This makes it…

  • CVE-2025-6215MedJul 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, …

  • CVE-2025-6721MedJul 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to…

  • CVE-2025-6720MedJul 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear log files.

  • CVE-2025-5811MedJul 18, 2025
    risk 0.34cvss 5.3epss 0.00

    The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and including, 2.7. This makes it possible for unauthenticated attackers to delete…

  • CVE-2025-3871MedJul 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this…

  • CVE-2025-53986MedJul 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hestia: from n/a through <= 3.2.10.

  • CVE-2025-48166MedJul 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in sminozzi Stop and Block bots plugin Anti bots antibots allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Stop and Block bots plugin Anti bots: from n/a through <= 1.48.

  • CVE-2025-30929MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects fluXtore: from n/a through <= 1.6.0.

  • CVE-2025-29012MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 7 Mailchimp Add-on: from n/a through < 2.4.

  • CVE-2025-24757MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.2.

  • CVE-2025-24748MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

  • CVE-2025-53304MedJun 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Rohil Contact Form – 7 : Hide Success Message contact-form-7-hide-success-message allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact Form – 7 : Hide Success Message: from n/a through <= 1.1.4.

  • CVE-2025-53295MedJun 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in iCount iCount Payment Gateway icount allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iCount Payment Gateway: from n/a through <= 2.0.7.

  • CVE-2025-53255MedJun 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HurryTimer: from n/a through <= 2.13.1.

  • CVE-2025-5813MedJun 26, 2025
    risk 0.34cvss 5.3epss 0.00

    The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for…

  • CVE-2025-49997MedJun 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.18.

  • CVE-2025-49996MedJun 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.4.

  • CVE-2025-49993MedJun 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in csarturas Cookie-Script.com cookie-script-com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookie-Script.com: from n/a through <= 1.2.1.

  • CVE-2025-49991MedJun 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.