VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 282 of 473
  • CVE-2025-24705MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Quick View: from n/a through <= 1.1.1.

  • CVE-2025-24633MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0.

  • CVE-2025-24596MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Table Lite: from n/a through <= 3.8.7.

  • CVE-2024-13361MedJan 22, 2025
    risk 0.34cvss 6.3epss 0.00

    The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attackers, with…

  • CVE-2025-21514MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.01

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-21498MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.01

    Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. …

  • CVE-2024-12104MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This…

  • CVE-2024-12071MedJan 18, 2025
    risk 0.34cvss 5.3epss 0.00

    The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_network_post() function in all versions up to, and including, 1.4.4. This…

  • CVE-2024-12370MedJan 17, 2025
    risk 0.34cvss 5.3epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.

  • CVE-2025-23862MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot contact-form-7-anti-spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through <= 1.0.1.

  • CVE-2025-23764MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.

  • CVE-2025-23514MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through <= 1.2.

  • CVE-2024-12427MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.00

    The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited…

  • CVE-2025-22737MedJan 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through <= 1.8.5.

  • CVE-2024-12006MedJan 14, 2025
    risk 0.34cvss 5.3epss 0.01

    The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as…

  • CVE-2024-13312MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.

  • CVE-2024-13303MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.

  • CVE-2024-43662MedJan 9, 2025
    risk 0.34cvss epss 0.01

    The .exe or .exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the user interface for uploading files is only shown to the iocadmin user. This issue affects Iocharger firmware for AC models…

  • CVE-2024-12713MedJan 8, 2025
    risk 0.34cvss 5.3epss 0.00

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated…

  • CVE-2025-22363MedJan 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for-woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through <= 1.1.