VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 291 of 473
  • CVE-2024-50459MedOct 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AidWP: from n/a through <= 3.2.3.

  • CVE-2024-9686MedOct 25, 2024
    risk 0.34cvss 5.3epss 0.00

    The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers…

  • CVE-2024-48932MedOct 24, 2024
    risk 0.34cvss 5.3epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http:///v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization.…

  • CVE-2024-43924MedOct 23, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.

  • CVE-2024-10003MedOct 22, 2024
    risk 0.34cvss 6.3epss 0.00

    The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 3.0.0.2903. This makes it possible for authenticated attackers, with…

  • CVE-2024-9671MedOct 9, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

  • CVE-2024-8430MedOct 1, 2024
    risk 0.34cvss 5.3epss 0.00

    The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated…

  • CVE-2024-9189MedSep 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for…

  • CVE-2024-7491MedSep 25, 2024
    risk 0.34cvss 5.3epss 0.00

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled…

  • CVE-2024-40852MedSep 17, 2024
    risk 0.34cvss 5.3epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.

  • CVE-2024-7727MedSep 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32.…

  • CVE-2024-8369MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for…

  • CVE-2024-8195MedAug 28, 2024
    risk 0.34cvss 5.3epss 0.01

    The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for…

  • CVE-2024-43214MedAug 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

  • CVE-2024-7390MedAug 21, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to change…

  • CVE-2023-4730MedAug 17, 2024
    risk 0.34cvss 5.3epss 0.00

    The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety…

  • CVE-2023-4027MedAug 17, 2024
    risk 0.34cvss 5.3epss 0.00

    The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings.

  • CVE-2023-4024MedAug 17, 2024
    risk 0.34cvss 5.3epss 0.01

    The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances.

  • CVE-2024-37930MedAug 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpress-magazine.This issue affects SmartMag: from n/a through < 10.1.0.

  • CVE-2024-43045MedAug 7, 2024
    risk 0.34cvss 6.3epss 0.04

    Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".