VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,365)

page 330 of 469
  • CVE-2025-12526MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with…

  • CVE-2025-42899MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on confidentiality of the application with no impact on integrity and availability of the application.

  • CVE-2025-42882MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment…

  • CVE-2025-48878MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version…

  • CVE-2025-64684MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

  • CVE-2025-12924MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack…

  • CVE-2025-12167MedNov 8, 2025
    risk 0.28cvss 4.3epss 0.00

    The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_aweber_logreset' AJAX endpoint in all versions up to, and including, 0.1.42. This makes it possible for authenticated…

  • CVE-2025-12527MedNov 7, 2025
    risk 0.28cvss 4.3epss 0.00

    The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capability check on the 'yydev_notes_save_dashboard_data' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers,…

  • CVE-2025-62028MedNov 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeNectar Salient salient.This issue affects Salient: from n/a through < 17.4.0.

  • CVE-2025-39465MedNov 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through <= 5.8.4.

  • CVE-2025-12675MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2025-11373MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability checks in the "depicter-media-upload"…

  • CVE-2025-12582MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all versions up to, and including, 0.0.2. This makes it possible for authenticated attackers, with…

  • CVE-2025-12389MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with…

  • CVE-2025-12156MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for…

  • CVE-2025-64358MedOct 31, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from n/a through <= 2.2.3.

  • CVE-2025-64356MedOct 31, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from n/a through <= 1.4.3.

  • CVE-2025-64148MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2025-64142MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2025-64139MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.