VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 408 of 464
  • CVE-2026-3056MedMar 4, 2026
    risk 0.21cvss 4.3epss 0.00

    The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. This makes it possible for authenticated…

  • CVE-2026-3351MedMar 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

  • CVE-2026-27457MedFeb 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user…

  • CVE-2026-27484MedFeb 21, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context. In setups where Discord moderation…

  • CVE-2026-25313MedFeb 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14.

  • CVE-2025-14342MedFeb 19, 2026
    risk 0.21cvss 4.3epss 0.00

    The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sq_ajax_uninstall function in all versions up to, and including, 12.4.14. This makes it possible for authenticated attackers, with…

  • CVE-2026-1860MedFeb 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the…

  • CVE-2025-12356MedFeb 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This makes it possible for…

  • CVE-2026-1925MedFeb 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for…

  • CVE-2025-14350MedFeb 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and…

  • CVE-2026-0998MedFeb 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and…

  • CVE-2026-2312MedFeb 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a user controlled key. This makes…

  • CVE-2026-1254MedFeb 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating…

  • CVE-2026-25633MedFeb 11, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are…

  • CVE-2026-24996MedFeb 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPElemento Importer: from n/a through <= 0.6.4.

  • CVE-2026-24636MedJan 23, 2026
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.9.1.

  • CVE-2025-13921MedJan 23, 2026
    risk 0.21cvss 4.3epss 0.00

    The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unauthorized modification or loss of data due to a missing capability check on the 'wedocs_user_documentation_handling_capabilities' function in all versions up…

  • CVE-2026-20888MedJan 22, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

  • CVE-2026-1003MedJan 16, 2026
    risk 0.21cvss 4.3epss 0.00

    The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with…

  • CVE-2025-14384MedJan 16, 2026
    risk 0.21cvss 4.3epss 0.00

    The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in all versions up to, and including, 4.9.2. This…