VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 373 of 464
  • CVE-2024-24718MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.

  • CVE-2024-24711MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

  • CVE-2024-23520MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.

  • CVE-2023-25039MedMar 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.

  • CVE-2022-45349MedMar 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

  • CVE-2023-37885MedMar 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

  • CVE-2023-33923MedMar 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0.

  • CVE-2023-30480MedMar 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.

  • CVE-2024-24840MedMar 23, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.

  • CVE-2024-24835MedMar 23, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.

  • CVE-2024-27190MedMar 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.

  • CVE-2024-1844MedMar 20, 2024
    risk 0.28cvss 4.3epss 0.00

    The RevivePress – Keep your Old Content Evergreen plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the import_data and copy_data functions in all versions up to, and including, 1.5.6. This makes it possible…

  • CVE-2024-1843MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.01

    The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access…

  • CVE-2024-1158MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.01

    The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buddyforms_new_page function in all…

  • CVE-2024-1127MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.01

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated…

  • CVE-2024-1126MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all versions up to, and including, 3.4.2. This makes it possible for…

  • CVE-2024-0829MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.01

    The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated…

  • CVE-2024-0377MedMar 13, 2024
    risk 0.28cvss 5.3epss 0.01

    The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated…

  • CVE-2024-0369MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.00

    The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with…

  • CVE-2024-1137MedMar 12, 2024
    risk 0.28cvss 4.3epss 0.00

    The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients. Affected releases are TIBCO Software Inc.'s TIBCO…