VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 278 of 473
  • CVE-2024-13307MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites'…

  • CVE-2025-46247MedApr 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

  • CVE-2025-46244MedApr 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3.

  • CVE-2025-39457MedApr 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8.

  • CVE-2025-39531MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in slazzercom Slazzer Background Changer slazzer-background-changer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Slazzer Background Changer: from n/a through <= 3.14.

  • CVE-2025-39513MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND activedemand allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ActiveDEMAND: from n/a through <= 0.2.46.

  • CVE-2025-32260MedApr 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.

  • CVE-2025-32259MedApr 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Alimir WP ULike wp-ulike.This issue affects WP ULike: from n/a through <= 4.7.9.1.

  • CVE-2025-26888MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through <= 5.3.8.

  • CVE-2025-31042MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sandwich Adsense: from n/a through <= 4.0.2.

  • CVE-2025-31012MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4.

  • CVE-2025-26657MedApr 8, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability.

  • CVE-2025-2789MedApr 5, 2025
    risk 0.34cvss 5.3epss 0.00

    The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in…

  • CVE-2025-32258MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in InfoGiants Simple Website Logo simple-website-logo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Website Logo: from n/a through <= 1.1.

  • CVE-2025-32254MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7.

  • CVE-2025-32253MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Course Booking System: from n/a through <= 6.1.

  • CVE-2025-32252MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Genealogy – Your Family History Website: from n/a through <= 0.1.9.

  • CVE-2025-32225MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Event Manager WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through <= 3.2.0.

  • CVE-2025-31628MedApr 1, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0.

  • CVE-2025-31872MedApr 1, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6.