VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 414 of 464
  • CVE-2024-10532MedNov 21, 2024
    risk 0.21cvss 4.3epss 0.01

    The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2024-10528MedNov 21, 2024
    risk 0.21cvss 4.3epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and…

  • CVE-2024-11154MedNov 20, 2024
    risk 0.21cvss 4.3epss 0.00

    The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for…

  • CVE-2024-10614MedNov 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with…

  • CVE-2024-10533MedNov 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up to, and including, 3.6.8. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2024-10786MedNov 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with…

  • CVE-2021-3987MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary…

  • CVE-2024-10897MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in all versions up to, and including, 2.1.5. This makes it possible for authenticated…

  • CVE-2024-10530MedNov 13, 2024
    risk 0.21cvss 4.3epss 0.00

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with…

  • CVE-2024-7429MedNov 5, 2024
    risk 0.21cvss 4.3epss 0.00

    The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with…

  • CVE-2024-43981MedNov 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.

  • CVE-2024-43968MedNov 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.

  • CVE-2024-10399MedOct 30, 2024
    risk 0.21cvss 4.3epss 0.00

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with…

  • CVE-2024-10437MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajax_enable function in all versions up to, and including, 4.2.1. This makes it possible for authenticated…

  • CVE-2024-50052MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

  • CVE-2024-10092MedOct 26, 2024
    risk 0.21cvss 4.3epss 0.00

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with…

  • CVE-2024-9109MedOct 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.12. This makes it possible for…

  • CVE-2024-8667MedOct 24, 2024
    risk 0.21cvss 4.3epss 0.00

    The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This…

  • CVE-2024-9583MedOct 23, 2024
    risk 0.21cvss 4.3epss 0.00

    The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12.…

  • CVE-2024-9891MedOct 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This…