VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (4,569)

page 33 of 229
  • CVE-2024-31297HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

  • CVE-2024-1934HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.

  • CVE-2024-27911HigApr 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

  • CVE-2024-30487HigMar 29, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.

  • CVE-2024-2848HigMar 29, 2024
    risk 0.49cvss 7.5epss 0.00

    The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to inject arbitrary HTML content into the site's footer.

  • CVE-2024-1169HigMar 7, 2024
    risk 0.49cvss 7.5epss 0.01

    The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyforms_upload_handle_dropped_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.

  • CVE-2024-1217HigFeb 29, 2024
    risk 0.49cvss 7.6epss 0.00

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

  • CVE-2023-5426HigOct 28, 2023
    risk 0.49cvss 7.5epss 0.00

    The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to delete user, term, and post meta belonging to arbitrary users.

  • CVE-2023-5132HigOct 21, 2023
    risk 0.49cvss 7.5epss 0.01

    The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteRequest function in versions up to, and including, 6.0.1. This makes it possible for unauthenticated attackers with knowledge of an existing WooCommerce Order ID to expose sensitive WooCommerce order information (e.g., Name, Address, Email Address, and other order metadata).

  • CVE-2022-4943HigOct 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.

  • CVE-2023-3714HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.00

    The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.

  • CVE-2021-4355HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.

  • CVE-2021-4348HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and conduct attacks such as redirecting visitors to malicious sites.

  • CVE-2021-4339HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all users and their email address in the database.

  • CVE-2020-36696HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

  • CVE-2017-10846HigSep 15, 2017
    risk 0.49cvss 7.5epss 0.00

    Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.

  • CVE-2017-1002151HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.00

    Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization

  • CVE-2017-1002007HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.05

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

  • CVE-2017-1002006HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.05

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

  • CVE-2017-7548HigAug 16, 2017
    risk 0.49cvss 7.5epss 0.01

    PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.