VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 368 of 464
  • CVE-2024-30517MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.

  • CVE-2024-30515MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.

  • CVE-2024-31294MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1.

  • CVE-2024-30537MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0.

  • CVE-2024-21748MedJun 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.

  • CVE-2024-1689MedJun 7, 2024
    risk 0.28cvss 4.3epss 0.00

    The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all versions up to, and including, 1.2.9. This makes it possible for authenticated attackers, with…

  • CVE-2024-5665MedJun 6, 2024
    risk 0.28cvss 4.3epss 0.00

    The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-4788MedJun 6, 2024
    risk 0.28cvss 4.3epss 0.00

    The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_bhf_post function in all versions up to, and including, 1.3.5. This makes it possible for authenticated…

  • CVE-2024-35674MedJun 5, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.109.

  • CVE-2024-30484MedJun 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Elementor: from n/a through 2.0.

  • CVE-2023-28494MedJun 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.

  • CVE-2024-1717MedJun 4, 2024
    risk 0.28cvss 4.3epss 0.00

    The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_ajax_call() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-28492MedJun 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.

  • CVE-2023-27460MedJun 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34.

  • CVE-2023-26523MedJun 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120.

  • CVE-2023-26521MedJun 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CodePeople Search in Place allows Functionality Misuse.This issue affects Search in Place: from n/a through 1.0.104.

  • CVE-2024-34803MedJun 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

  • CVE-2024-4427MedMay 30, 2024
    risk 0.28cvss 4.3epss 0.00

    The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or…

  • CVE-2024-0893MedMay 24, 2024
    risk 0.28cvss 4.3epss 0.00

    The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber…

  • CVE-2024-3711MedMay 23, 2024
    risk 0.28cvss 4.3epss 0.00

    The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and action_request_enable in all versions up to, and including, 2.4.43. This…