VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 372 of 464
  • CVE-2024-3662MedApr 13, 2024
    risk 0.28cvss 4.3epss 0.00

    The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with…

  • CVE-2023-51499MedApr 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipping Per Product: from n/a through 2.5.4.

  • CVE-2024-25935MedApr 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.

  • CVE-2024-25908MedApr 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

  • CVE-2024-24883MedApr 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.11.10.

  • CVE-2022-47604MedApr 11, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in junkcoder, ristoniinemets AJAX Thumbnail Rebuild.This issue affects AJAX Thumbnail Rebuild: from n/a through 1.13.

  • CVE-2024-3213MedApr 9, 2024
    risk 0.28cvss 5.3epss 0.01

    The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated…

  • CVE-2024-2543MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.01

    The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the…

  • CVE-2024-2222MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.01

    The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated…

  • CVE-2023-6965MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.01

    The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion…

  • CVE-2024-30217MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the…

  • CVE-2024-30216MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of…

  • CVE-2024-1994MedApr 6, 2024
    risk 0.28cvss 4.3epss 0.00

    The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-30463MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.

  • CVE-2024-2476MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2024-2844MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to…

  • CVE-2024-29240MedMar 28, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via unspecified vectors.

  • CVE-2024-30235MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.

  • CVE-2023-52214MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3.

  • CVE-2024-24719MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.