VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 371 of 464
  • CVE-2024-33686MedApr 29, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a…

  • CVE-2024-32822MedApr 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in impleCode Reviews Plus.This issue affects Reviews Plus: from n/a through 1.3.4.

  • CVE-2024-32829MedApr 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.

  • CVE-2024-32828MedApr 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Octolize Flexible Shipping.This issue affects Flexible Shipping: from n/a through 4.24.15.

  • CVE-2023-52220MedApr 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0.

  • CVE-2024-32432MedApr 24, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Ovic Team Ovic Addon Toolkit.This issue affects Ovic Addon Toolkit: from n/a through 2.6.1.

  • CVE-2024-0900MedApr 23, 2024
    risk 0.28cvss 4.3epss 0.00

    The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! plugin for WordPress is vulnerable to unauthorized post creation due to a missing capability check on the elespare_create_post() function…

  • CVE-2024-3664MedApr 23, 2024
    risk 0.28cvss 4.3epss 0.00

    The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible for authenticated…

  • CVE-2024-32687MedApr 22, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.

  • CVE-2024-32681MedApr 22, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.

  • CVE-2024-32689MedApr 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.

  • CVE-2024-32525MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6.

  • CVE-2024-32524MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2.

  • CVE-2024-32522MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Jaed Mosharraf & Pluginbazar Team Open Close WooCommerce Store.This issue affects Open Close WooCommerce Store: from n/a through 4.9.1.

  • CVE-2024-32520MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.

  • CVE-2024-32519MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in GutenGeek GG Woo Feed for WooCommerce.This issue affects GG Woo Feed for WooCommerce: from n/a through 1.2.6.

  • CVE-2024-32517MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12.

  • CVE-2024-32516MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.

  • CVE-2024-32455MedApr 16, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from n/a through 1.5.2.

  • CVE-2024-31421MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.