VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 366 of 464
  • CVE-2024-32148MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.

  • CVE-2024-35671MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.

  • CVE-2024-34824MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

  • CVE-2023-52217MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

  • CVE-2023-33922MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

  • CVE-2023-6748MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data…

  • CVE-2024-4746MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.32.

  • CVE-2024-4745MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways and Contests by RafflePress: from n/a through 1.12.4.

  • CVE-2024-35741MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

  • CVE-2024-35727MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.

  • CVE-2024-35726MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.

  • CVE-2024-35725MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6.

  • CVE-2024-35724MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12.

  • CVE-2024-35723MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.2.0.

  • CVE-2024-35722MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through 1.4.0.

  • CVE-2024-35721MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5.

  • CVE-2024-35720MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.

  • CVE-2024-35717MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through 1.3.9.

  • CVE-2024-22296MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.

  • CVE-2024-32081MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.