VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 369 of 464
  • CVE-2024-3626MedMay 23, 2024
    risk 0.28cvss 4.3epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and…

  • CVE-2024-3663MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    The WP Scraper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_scraper_multi_scrape_action() function in all versions up to, and including, 5.7. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2023-32129MedMay 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.

  • CVE-2024-3609MedMay 16, 2024
    risk 0.28cvss 4.3epss 0.00

    The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible…

  • CVE-2024-4199MedMay 15, 2024
    risk 0.28cvss 4.3epss 0.00

    The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-4139MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application.…

  • CVE-2024-4138MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of…

  • CVE-2024-4444MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated…

  • CVE-2024-33956MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

  • CVE-2024-33942MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.

  • CVE-2023-6327MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to…

  • CVE-2024-4233MedMay 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes:…

  • CVE-2024-33574MedMay 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.

  • CVE-2024-33573MedMay 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1.

  • CVE-2024-24833MedMay 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.

  • CVE-2024-33570MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

  • CVE-2024-34389MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

  • CVE-2024-34387MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

  • CVE-2024-34377MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.

  • CVE-2024-34371MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18.