VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,368)

page 318 of 469
  • CVE-2026-2658MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unknown function of the component Multiple Endpoints. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is…

  • CVE-2026-1655MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and…

  • CVE-2026-2633MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` function which handles the…

  • CVE-2026-1640MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.0.2. This is due to missing authorization checks on the project and task comment submission functions (AJAX…

  • CVE-2026-1906MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action due to missing capability checks and order…

  • CVE-2025-12075MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wos_troubleshooting' AJAX endpoint in all versions up to, and including, 5.3.5. This makes it possible for authenticated attackers, with…

  • CVE-2026-2608MedFeb 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with…

  • CVE-2026-0929MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

  • CVE-2026-2022MedFeb 14, 2026
    risk 0.28cvss 4.3epss 0.00

    The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible for authenticated attackers, with…

  • CVE-2026-1748MedFeb 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with…

  • CVE-2025-15524MedFeb 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with…

  • CVE-2025-14895MedFeb 10, 2026
    risk 0.28cvss 5.4epss 0.00

    The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API endpoint. This makes it possible for authenticated…

  • CVE-2026-24327MedFeb 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on…

  • CVE-2026-24326MedFeb 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity,…

  • CVE-2026-23688MedFeb 10, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

  • CVE-2026-23681MedFeb 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the…

  • CVE-2025-15476MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bucketlister_do_admin_ajax() function in all versions up to, and including, 0.1.5. This makes it possible for authenticated attackers, with…

  • CVE-2025-15327MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Deploy.

  • CVE-2025-15326MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Patch.

  • CVE-2026-1927MedFeb 5, 2026
    risk 0.28cvss 5.4epss 0.00

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the greenshift_app_pass_validation() function in all versions up to, and including, 12.6. This makes it possible for…