VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 397 of 464
  • CVE-2024-3608MedJul 9, 2024
    risk 0.27cvss 5.3epss 0.01

    The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to…

  • CVE-2024-6088MedJul 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to…

  • CVE-2024-5541MedJun 18, 2024
    risk 0.27cvss 5.3epss 0.00

    The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it…

  • CVE-2024-37296MedJun 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g.…

  • CVE-2024-4319MedJun 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download…

  • CVE-2024-30529MedJun 9, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.7.

  • CVE-2024-36036MedMay 27, 2024
    risk 0.27cvss 4.2epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

  • CVE-2024-4858MedMay 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for…

  • CVE-2023-6325MedMay 23, 2024
    risk 0.27cvss 5.3epss 0.00

    The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it…

  • CVE-2024-3268MedMay 21, 2024
    risk 0.27cvss 5.3epss 0.00

    The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including,…

  • CVE-2024-4280MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.00

    The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.

  • CVE-2024-3897MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This makes it possible for unauthenticated…

  • CVE-2024-3599MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for…

  • CVE-2024-3287MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection due to a missing capability check on the save_settings function in all versions up to, and including, 3.10.2. This makes it possible…

  • CVE-2024-2797MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This…

  • CVE-2024-0908MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the apbPosts() function hooked via an AJAX action in all versions up to, and including, 1.13.4.…

  • CVE-2024-3678MedApr 26, 2024
    risk 0.27cvss 5.3epss 0.01

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

  • CVE-2023-52211MedApr 12, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0.0.

  • CVE-2024-23944MedMar 15, 2024
    risk 0.27cvss 5.3epss 0.00

    Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't…

  • CVE-2024-1322MedFeb 29, 2024
    risk 0.27cvss 5.3epss 0.01

    The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes…