VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 292 of 473
  • CVE-2024-2508MedJul 31, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up to, and including, 2.8.4.4. This makes it possible for unauthenticated attackers to add the…

  • CVE-2024-1798MedJul 27, 2024
    risk 0.34cvss 5.3epss 0.00

    The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to export…

  • CVE-2024-5861MedJul 24, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated…

  • CVE-2024-6455MedJul 18, 2024
    risk 0.34cvss 5.3epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item…

  • CVE-2024-5545MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for…

  • CVE-2024-3961MedJun 21, 2024
    risk 0.34cvss 5.3epss 0.00

    The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it…

  • CVE-2024-3610MedJun 21, 2024
    risk 0.34cvss 5.3epss 0.01

    The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to…

  • CVE-2024-4450MedJun 19, 2024
    risk 0.34cvss 6.3epss 0.00

    The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxController.php file in all versions up to, and including, 3.3.6. This makes it possible for…

  • CVE-2024-23504MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

  • CVE-2023-51496MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

  • CVE-2023-51377MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

  • CVE-2023-51507MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

  • CVE-2023-37394MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.

  • CVE-2023-35040MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

  • CVE-2023-51413MedJun 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

  • CVE-2023-41240MedJun 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

  • CVE-2023-40603MedJun 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

  • CVE-2023-51537MedJun 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

  • CVE-2024-34768MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

  • CVE-2024-34763MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.5.