VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 281 of 473
  • CVE-2025-1502MedMar 1, 2025
    risk 0.34cvss 5.3epss 0.00

    The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in all versions up to, and including, 1.33.3. This makes it possible for unauthenticated…

  • CVE-2025-1249MedFeb 26, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through <= 6.6.4.1.

  • CVE-2025-26975MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3.

  • CVE-2024-13693MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included…

  • CVE-2025-1402MedFeb 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with…

  • CVE-2024-13231MedFeb 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_video' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated…

  • CVE-2024-13719MedFeb 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…

  • CVE-2025-27013MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7.

  • CVE-2024-13316MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and…

  • CVE-2025-22291MedFeb 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide…

  • CVE-2024-13554MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes it possible for unauthenticated…

  • CVE-2025-23187MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

  • CVE-2024-11133MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to download event…

  • CVE-2025-22686MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from n/a through <= 5.0.17.

  • CVE-2024-12620MedFeb 1, 2025
    risk 0.34cvss 5.3epss 0.00

    The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'agl_json' AJAX action in all versions up to, and including, 1.4.23. This makes it…

  • CVE-2024-12184MedFeb 1, 2025
    risk 0.34cvss 5.3epss 0.00

    The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for…

  • CVE-2025-24747MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0.

  • CVE-2025-24662MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.

  • CVE-2025-24600MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5.

  • CVE-2025-24590MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in picu picu picu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects picu: from n/a through <= 2.4.0.