VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 418 of 464
  • CVE-2024-1400MedMar 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or…

  • CVE-2024-0052LowMar 11, 2024
    risk 0.21cvss 3.3epss 0.00

    In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-1870MedMar 9, 2024
    risk 0.21cvss 4.3epss 0.00

    The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with…

  • CVE-2024-2298MedMar 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers,…

  • CVE-2024-28155MedMar 6, 2024
    risk 0.21cvss 4.3epss 0.00

    Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names.

  • CVE-2024-1218MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This…

  • CVE-2024-1091MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with…

  • CVE-2024-1090MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers,…

  • CVE-2024-1089MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optimizeAllOn function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with…

  • CVE-2024-0984MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated…

  • CVE-2024-0983MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers,…

  • CVE-2024-0766MedFeb 28, 2024
    risk 0.21cvss 4.3epss 0.00

    The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including, 1.4.4. This makes it possible for…

  • CVE-2024-1653MedFeb 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-1652MedFeb 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-1650MedFeb 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-1649MedFeb 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-1686MedFeb 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, and including, 1.1.2 via the apply_layout function due to a missing capability check. This makes it possible for…

  • CVE-2024-1053MedFeb 22, 2024
    risk 0.21cvss 4.3epss 0.00

    The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level…

  • CVE-2024-0037LowFeb 16, 2024
    risk 0.21cvss 3.3epss 0.00

    In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2024-1078MedFeb 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers,…