VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 419 of 464
  • CVE-2024-0797MedFeb 5, 2024
    risk 0.21cvss 4.3epss 0.00

    The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This…

  • CVE-2023-4637MedFeb 5, 2024
    risk 0.21cvss 4.3epss 0.01

    The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these…

  • CVE-2024-0836MedJan 31, 2024
    risk 0.21cvss 4.3epss 0.00

    The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible…

  • CVE-2022-23180MedJan 16, 2024
    risk 0.21cvss 4.3epss 0.01

    The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

  • CVE-2023-7019MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible…

  • CVE-2023-6742MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This makes it…

  • CVE-2023-6598MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions…

  • CVE-2023-6504MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and…

  • CVE-2023-6883MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2023-50769MedDec 13, 2023
    risk 0.21cvss 4.3epss 0.00

    Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2023-50765MedDec 13, 2023
    risk 0.21cvss 4.3epss 0.00

    A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.

  • CVE-2023-5419MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5417MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_update_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5416MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5415MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_add_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5411MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_save_post function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5387MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_trigger_dark_mode function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with…

  • CVE-2023-5385MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-5314MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers,…

  • CVE-2023-4686MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including…