VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,365)

page 336 of 469
  • CVE-2025-58617MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in FAKTOR VIER F4 Media Taxonomies f4-media-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects F4 Media Taxonomies: from n/a through <= 1.1.4.

  • CVE-2025-58601MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Classified Listing: from n/a through <= 5.0.6.

  • CVE-2025-58599MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.1.0.

  • CVE-2025-58594MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy: from n/a through <= 2.7.12.

  • CVE-2025-3701MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through <= 16.8.

  • CVE-2025-9747MedAug 31, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery. The attack can be executed remotely. The exploit has been disclosed to…

  • CVE-2025-48350MedAug 28, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Basar Ventures AutoWP autowp-ai-content-writer-rewriter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AutoWP: from n/a through <= 2.2.7.

  • CVE-2025-0951MedAug 28, 2025
    risk 0.28cvss 4.3epss 0.00

    Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2025-58193MedAug 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.7.0.1.

  • CVE-2025-58192MedAug 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bulk Delete: from n/a through <= 1.3.6.

  • CVE-2024-8860MedAug 26, 2025
    risk 0.28cvss 4.3epss 0.00

    The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function,…

  • CVE-2025-7828MedAug 23, 2025
    risk 0.28cvss 4.3epss 0.00

    The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_listing_page() function in all versions up to, and including, 0.4. This makes it possible for authenticated attackers, with…

  • CVE-2025-7827MedAug 23, 2025
    risk 0.28cvss 4.3epss 0.00

    The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ni_woocpr_action() function in all versions up to, and including, 1.2.4. This makes it possible for authenticated…

  • CVE-2025-9331MedAug 22, 2025
    risk 0.28cvss 4.3epss 0.00

    The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with…

  • CVE-2025-57894MedAug 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ollybach WPPizza wppizza allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPPizza: from n/a through <= 3.19.8.

  • CVE-2025-57884MedAug 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 12.1.1.

  • CVE-2025-49396MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in themifyme Themify Builder themify-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Themify Builder: from n/a through <= 7.6.7.

  • CVE-2025-9202MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with…

  • CVE-2025-8357MedAug 19, 2025
    risk 0.28cvss 4.3epss 0.00

    The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including,…

  • CVE-2025-8996MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.