VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 370 of 464
  • CVE-2024-1050MedMay 4, 2024
    risk 0.28cvss 4.3epss 0.00

    The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for…

  • CVE-2024-33937MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.

  • CVE-2024-33925MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

  • CVE-2024-33915MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.

  • CVE-2024-33914MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.

  • CVE-2024-24710MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.

  • CVE-2023-44472MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.

  • CVE-2024-3936MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes…

  • CVE-2024-3607MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2024-3585MedMay 2, 2024
    risk 0.28cvss 5.3epss 0.01

    The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on the hooks function in all versions up to, and including, 1.0.2.3. This makes it possible for unauthenticated attackers to download…

  • CVE-2024-3581MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber…

  • CVE-2024-3546MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wp_mgdp_populate_popup function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with…

  • CVE-2024-3275MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to…

  • CVE-2024-3206MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax() function in all versions up to, and including, 2.3.2. This makes it possible for authenticated…

  • CVE-2024-3071MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the acfg_update_fields() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-6731MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to…

  • CVE-2024-3072MedApr 30, 2024
    risk 0.28cvss 4.3epss 0.00

    The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-33585MedApr 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This issue affects Payment Gateway Based Fees and Discounts for WooCommerce: from n/a through 2.12.1.

  • CVE-2024-33595MedApr 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

  • CVE-2024-33593MedApr 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.