VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 295 of 473
  • CVE-2024-30539MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

  • CVE-2024-30538MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4.

  • CVE-2023-51494MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.

  • CVE-2024-22151MedJun 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.

  • CVE-2024-35659MedJun 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.

  • CVE-2024-1175MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated…

  • CVE-2024-0972MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be…

  • CVE-2024-30525MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

  • CVE-2024-4997MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password…

  • CVE-2024-1324MedJun 1, 2024
    risk 0.34cvss 5.3epss 0.00

    The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function hooked via a norpriv AJAX in all versions up to, and including, 1.9.8. This makes it…

  • CVE-2023-43846MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.01

    Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device logs via HTTP GET request. The logs contain such information as user names and IP addresses used in the infrastructure. This…

  • CVE-2024-35174MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.

  • CVE-2024-32802MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.

  • CVE-2023-34186MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.

  • CVE-2023-33321MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.

  • CVE-2022-45070MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.

  • CVE-2024-3915MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.00

    The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update…

  • CVE-2024-32719MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

  • CVE-2024-1229MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to…

  • CVE-2024-30459MedMay 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.