VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 395 of 464
  • CVE-2025-1508MedMar 12, 2025
    risk 0.27cvss 5.3epss 0.00

    The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2025-1404MedMar 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_sccp_reports_user_search() function in all versions up to, and including, 4.4.7. This makes it possible for…

  • CVE-2025-1483MedFeb 20, 2025
    risk 0.27cvss 5.3epss 0.00

    The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engtz_wd_save_dropship AJAX endpoint in all versions up to, and including, 2.3.12. This makes it possible for…

  • CVE-2024-13520MedFeb 20, 2025
    risk 0.27cvss 5.3epss 0.00

    The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all…

  • CVE-2025-0968MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13364MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to reset the…

  • CVE-2025-25081MedFeb 7, 2025
    risk 0.27cvss 4.2epss 0.00

    Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.

  • CVE-2024-13371MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.01

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6.…

  • CVE-2024-12712MedJan 8, 2025
    risk 0.27cvss 5.3epss 0.00

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order…

  • CVE-2024-12316MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup…

  • CVE-2024-9697MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This makes it…

  • CVE-2024-12559MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for…

  • CVE-2023-45061MedJan 2, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in awsm.in WP Job Openings wp-job-openings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Openings: from n/a through <= 3.4.1.

  • CVE-2024-12413MedDec 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser',…

  • CVE-2024-11712MedDec 14, 2024
    risk 0.27cvss 5.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This…

  • CVE-2024-9706MedDec 6, 2024
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for…

  • CVE-2024-10580MedNov 27, 2024
    risk 0.27cvss 5.3epss 0.00

    The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for…

  • CVE-2024-10813MedNov 23, 2024
    risk 0.27cvss 5.3epss 0.01

    The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var…

  • CVE-2024-10393MedNov 21, 2024
    risk 0.27cvss 5.3epss 0.01

    The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-10861MedNov 16, 2024
    risk 0.27cvss 5.3epss 0.00

    The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it…