VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 296 of 473
  • CVE-2024-33908MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.

  • CVE-2024-33907MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.26.2.

  • CVE-2024-34372MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.

  • CVE-2024-33910MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

  • CVE-2024-33929MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

  • CVE-2024-33920MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.

  • CVE-2024-33941MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.

  • CVE-2023-25457MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slider: from n/a through 1.5.1.

  • CVE-2024-3601MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated…

  • CVE-2024-3312MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts.

  • CVE-2024-2109MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2024-2043MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.01

    The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for…

  • CVE-2024-1688MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales…

  • CVE-2024-1584MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1.…

  • CVE-2024-0629MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to…

  • CVE-2024-33587MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0.

  • CVE-2024-33586MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.

  • CVE-2024-33596MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.

  • CVE-2024-33652MedApr 29, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.

  • CVE-2024-32826MedApr 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Vektor,Inc. VK Block Patterns.This issue affects VK Block Patterns: from n/a through 1.31.0.