VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 299 of 473
  • CVE-2024-1044MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to…

  • CVE-2024-0907MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.01

    The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the restore_records() function in all versions up to, and including, 8.5.6. This makes it possible for…

  • CVE-2024-0516MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated…

  • CVE-2024-1516MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create…

  • CVE-2024-1368MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_page() function in all versions up to, and including, 0.1.1. This makes it possible for unauthenticated attackers to duplicate…

  • CVE-2024-1136MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated…

  • CVE-2024-1779MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.00

    The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and including, 1.1.1. This makes it possible for…

  • CVE-2024-1562MedFeb 21, 2024
    risk 0.34cvss 5.3epss 0.00

    The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers…

  • CVE-2024-0596MedFeb 10, 2024
    risk 0.34cvss 5.3epss 0.00

    The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated…

  • CVE-2024-1177MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.2.10. This makes it possible for unauthenticated…

  • CVE-2024-1121MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function in all versions up to, and including, 1.9.3.2. This makes it possible for unauthenticated attackers to export form…

  • CVE-2023-6557MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract…

  • CVE-2023-47148MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.

  • CVE-2024-0617MedJan 25, 2024
    risk 0.34cvss 5.3epss 0.00

    The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in all versions up to, and including, 4.12. This makes it possible for unauthenticated attackers to…

  • CVE-2023-48926MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

  • CVE-2024-0237MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

  • CVE-2024-0236MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

  • CVE-2023-6496MedJan 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

  • CVE-2023-48247MedJan 10, 2024
    risk 0.34cvss 5.3epss 0.01

    The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

  • CVE-2023-49003MedDec 27, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity.