VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 297 of 473
  • CVE-2024-32678MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5.

  • CVE-2024-32677MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.

  • CVE-2023-32127MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.

  • CVE-2023-25785MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Shoaib Saleem WP Post Rating allows Functionality Misuse.This issue affects WP Post Rating: from n/a through 2.5.

  • CVE-2024-32679MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16.

  • CVE-2024-32691MedApr 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.

  • CVE-2024-32684MedApr 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

  • CVE-2024-32601MedApr 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Popup Anything.This issue affects Popup Anything: from n/a through 2.8.

  • CVE-2024-1350MedApr 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Prasidhda Malla Honeypot for WP Comment.This issue affects Honeypot for WP Comment: from n/a through 2.2.3.

  • CVE-2024-32532MedApr 17, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.

  • CVE-2024-32518MedApr 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.

  • CVE-2024-31432MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in StellarWP Restrict Content.This issue affects Restrict Content: from n/a through 3.2.8.

  • CVE-2024-24850MedApr 11, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.

  • CVE-2024-31242MedApr 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

  • CVE-2024-31230MedApr 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.2.

  • CVE-2024-1984MedApr 9, 2024
    risk 0.34cvss 5.3epss 0.01

    The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated individuals to obtain post contents of password protected posts via the generated source.

  • CVE-2024-1587MedApr 9, 2024
    risk 0.34cvss 5.3epss 0.01

    The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.

  • CVE-2024-3216MedApr 6, 2024
    risk 0.34cvss 5.3epss 0.00

    The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This…

  • CVE-2024-27910MedApr 5, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

  • CVE-2024-1732MedApr 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for…