CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,262)
page 29 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-10008 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2024 | The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,… | ||
| CVE-2021-4447 | Hig | 0.57 | 8.8 | 0.00 | Oct 16, 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it… | ||
| CVE-2020-36837 | Cri | 0.57 | 9.9 | 0.01 | Oct 16, 2024 | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database.… | ||
| CVE-2024-21254 | Hig | 0.57 | 8.8 | 0.01 | Oct 15, 2024 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | ||
| CVE-2024-38179 | Hig | 0.57 | 8.8 | 0.00 | Oct 8, 2024 | Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | ||
| CVE-2024-47790 | Hig | 0.57 | — | 0.00 | Oct 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to… | ||
| CVE-2024-8102 | Hig | 0.57 | 8.8 | 0.00 | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to, and including,… | ||
| CVE-2024-7950 | Cri | 0.57 | 9.8 | 0.01 | Sep 4, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the… | ||
| CVE-2024-43247 | Hig | 0.57 | 8.8 | 0.00 | Aug 19, 2024 | Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5. | ||
| CVE-2024-6698 | Hig | 0.57 | 8.8 | 0.00 | Aug 1, 2024 | The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers,… | ||
| CVE-2024-37901 | Cri | 0.57 | 9.9 | 0.01 | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to… | ||
| CVE-2024-6328 | Cri | 0.57 | 9.8 | 0.01 | Jul 12, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and… | ||
| CVE-2024-21417 | Hig | 0.57 | 8.8 | 0.00 | Jul 10, 2024 | Windows Text Services Framework Elevation of Privilege Vulnerability | ||
| CVE-2024-5820 | Hig | 0.57 | 8.8 | 0.01 | Jun 27, 2024 | An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all listeners on the given socket, enabling any such malicious website… | ||
| CVE-2022-43453 | Hig | 0.57 | 8.8 | 0.00 | Jun 21, 2024 | Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41. | ||
| CVE-2023-46148 | Hig | 0.57 | 8.8 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | ||
| CVE-2024-33606 | Hig | 0.57 | 8.8 | 0.00 | Jun 11, 2024 | An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulnerability. | ||
| CVE-2024-33564 | Hig | 0.57 | 8.8 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. | ||
| CVE-2024-30485 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2024 | Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0. | ||
| CVE-2024-25092 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2024 | Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0. |
- risk 0.57cvss 8.8epss 0.01
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,…
- risk 0.57cvss 8.8epss 0.00
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it…
- risk 0.57cvss 9.9epss 0.01
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database.…
- risk 0.57cvss 8.8epss 0.01
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
- risk 0.57cvss 8.8epss 0.00
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
- risk 0.57cvss —epss 0.00
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to…
- risk 0.57cvss 8.8epss 0.00
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to, and including,…
- risk 0.57cvss 9.8epss 0.01
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the…
- risk 0.57cvss 8.8epss 0.00
Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5.
- risk 0.57cvss 8.8epss 0.00
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers,…
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to…
- risk 0.57cvss 9.8epss 0.01
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and…
- risk 0.57cvss 8.8epss 0.00
Windows Text Services Framework Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all listeners on the given socket, enabling any such malicious website…
- risk 0.57cvss 8.8epss 0.00
Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.
- risk 0.57cvss 8.8epss 0.00
Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- risk 0.57cvss 8.8epss 0.00
An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulnerability.
- risk 0.57cvss 8.8epss 0.00
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- risk 0.57cvss 8.8epss 0.01
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
- risk 0.57cvss 8.8epss 0.01
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.