VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,365)

page 349 of 469
  • CVE-2024-13811MedMar 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. This makes it possible for…

  • CVE-2024-13810MedMar 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'zass_import_zass' AJAX actions in all versions up to, and including, 3.9.9.10. This makes it possible for…

  • CVE-2024-13747MedMar 5, 2025
    risk 0.28cvss 4.3epss 0.00

    The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'template_delete_saved' function in all versions up to, and including, 3.0.34. This makes it possible for authenticated attackers,…

  • CVE-2024-13686MedMar 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with…

  • CVE-2025-1891MedMar 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

  • CVE-2025-1813MedMar 2, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and…

  • CVE-2025-1780MedMar 1, 2025
    risk 0.28cvss 4.3epss 0.00

    The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible…

  • CVE-2024-13358MedMar 1, 2025
    risk 0.28cvss 4.3epss 0.00

    The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.24. This makes it possible…

  • CVE-2024-10860MedFeb 28, 2025
    risk 0.28cvss 4.3epss 0.00

    The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check on the _submit_uninstall_reason_action() function in all versions up to, and including, 2.19.0. This makes it possible for…

  • CVE-2025-1745MedFeb 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to…

  • CVE-2025-1091MedFeb 26, 2025
    risk 0.28cvss 4.3epss 0.00

    A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if the URL is known.

  • CVE-2025-26983MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through <=…

  • CVE-2025-26948MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.

  • CVE-2025-26928MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Xfinitysoft Order Limit for WooCommerce wc-order-limit-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Limit for WooCommerce: from n/a through <= 3.0.2.

  • CVE-2025-26871MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.8.3.

  • CVE-2025-1644MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais/SG_Gravar. The manipulation of the argument idItAg leads to cross-site request forgery. It is possible to launch the attack…

  • CVE-2025-1643MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file /DadosPessoais/SG_AlterarSenha. The manipulation leads to cross-site request forgery. The attack may be initiated remotely.…

  • CVE-2025-1557MedFeb 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

  • CVE-2024-13783MedFeb 18, 2025
    risk 0.28cvss 4.3epss 0.00

    The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2024-13687MedFeb 18, 2025
    risk 0.28cvss 4.3epss 0.00

    The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_team_builder_options() function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers,…