VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 396 of 464
  • CVE-2024-10531MedNov 13, 2024
    risk 0.27cvss 5.3epss 0.01

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with…

  • CVE-2024-10529MedNov 13, 2024
    risk 0.27cvss 5.3epss 0.01

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with…

  • CVE-2024-47358MedNov 1, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.

  • CVE-2024-43277MedNov 1, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.

  • CVE-2024-49683MedOct 24, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5.

  • CVE-2024-9065MedOct 10, 2024
    risk 0.27cvss 5.3epss 0.00

    The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticated attackers to send…

  • CVE-2024-8513MedOct 10, 2024
    risk 0.27cvss 5.3epss 0.00

    The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_save_plugin_config() function in all versions up to, and including,…

  • CVE-2024-9025MedSep 26, 2024
    risk 0.27cvss 5.3epss 0.00

    The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated…

  • CVE-2024-8678MedSep 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated…

  • CVE-2024-8658MedSep 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data due to a missing…

  • CVE-2024-7381MedSep 5, 2024
    risk 0.27cvss 5.3epss 0.00

    The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to…

  • CVE-2024-5053MedSep 1, 2024
    risk 0.27cvss 4.2epss 0.00

    The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including,…

  • CVE-2024-5857MedAug 29, 2024
    risk 0.27cvss 5.3epss 0.00

    The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including,…

  • CVE-2024-7447MedAug 28, 2024
    risk 0.27cvss 5.3epss 0.00

    The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in all versions up to,…

  • CVE-2024-43331MedAug 22, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.

  • CVE-2024-5939MedAug 20, 2024
    risk 0.27cvss 5.3epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated…

  • CVE-2024-35686MedAug 18, 2024
    risk 0.27cvss 5.3epss 0.01

    Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

  • CVE-2023-4025MedAug 17, 2024
    risk 0.27cvss 5.3epss 0.00

    The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.

  • CVE-2024-6489MedJul 20, 2024
    risk 0.27cvss 5.3epss 0.00

    The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with…

  • CVE-2024-0619MedJul 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to update…