VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 364 of 464
  • CVE-2024-6175MedJul 18, 2024
    risk 0.28cvss 5.4epss 0.00

    The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, …

  • CVE-2024-6033MedJul 17, 2024
    risk 0.28cvss 4.3epss 0.00

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for…

  • CVE-2024-6621MedJul 16, 2024
    risk 0.28cvss 4.3epss 0.00

    The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up…

  • CVE-2024-6579MedJul 16, 2024
    risk 0.28cvss 4.3epss 0.00

    The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated…

  • CVE-2024-37544MedJul 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Saleswonder Team: Tobias Get Better Reviews for WooCommerce more-better-reviews-for-woocommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through <= 4.0.6.

  • CVE-2024-5677MedJul 10, 2024
    risk 0.28cvss 4.3epss 0.00

    The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the fig_save_after_generate_image function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with…

  • CVE-2024-6167MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2024-5993MedJul 9, 2024
    risk 0.28cvss 5.4epss 0.00

    The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-5856MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with…

  • CVE-2024-5648MedJul 9, 2024
    risk 0.28cvss 5.4epss 0.00

    The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. wrld_set_configuration, wrld_exclude_settings_save, apply_time_tracking_settings,…

  • CVE-2024-39596MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.

  • CVE-2024-37175MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.

  • CVE-2024-5855MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the bulk_action_delete and delete_single_image_call AJAX actions in all versions up to, and including, 3.0.1. This…

  • CVE-2024-5863MedJun 28, 2024
    risk 0.28cvss 5.4epss 0.00

    The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in all versions up to, and including, 1.13.5. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2023-51375MedJun 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.

  • CVE-2024-1955MedJun 21, 2024
    risk 0.28cvss 4.3epss 0.00

    The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers,…

  • CVE-2023-39993MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.

  • CVE-2023-39922MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

  • CVE-2023-47788MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

  • CVE-2024-38504MedJun 18, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles