VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 420 of 464
  • CVE-2023-4941MedOct 20, 2023
    risk 0.21cvss 4.3epss 0.00

    The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate…

  • CVE-2023-4943MedOct 20, 2023
    risk 0.21cvss 4.3epss 0.00

    The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to…

  • CVE-2023-4938MedOct 18, 2023
    risk 0.21cvss 4.3epss 0.00

    The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or…

  • CVE-2023-42469LowSep 13, 2023
    risk 0.21cvss 3.3epss 0.00

    The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity…

  • CVE-2023-2353MedAug 31, 2023
    risk 0.21cvss 4.3epss 0.01

    The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. This makes it possible for subscriber-level attackers to…

  • CVE-2023-3244MedAug 17, 2023
    risk 0.21cvss 4.3epss 0.01

    The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated…

  • CVE-2023-4374MedAug 16, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers…

  • CVE-2023-3426MedAug 2, 2023
    risk 0.21cvss 4.3epss 0.01

    The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

  • CVE-2023-0958MedJul 28, 2023
    risk 0.21cvss 4.3epss 0.01

    Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for…

  • CVE-2023-33880LowJul 12, 2023
    risk 0.21cvss 3.3epss 0.00

    In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-33879LowJul 12, 2023
    risk 0.21cvss 3.3epss 0.00

    In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-2869MedJul 12, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with…

  • CVE-2023-3315MedJun 19, 2023
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2023-2557MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.00

    The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with…

  • CVE-2023-2556MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.00

    The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible…

  • CVE-2023-2555MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.00

    The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers,…

  • CVE-2023-2189MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.01

    The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_widget function in versions up to, and including, 1.4.3. This makes it possible for authenticated…

  • CVE-2023-1169MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.01

    The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload…

  • CVE-2023-2715MedMay 20, 2023
    risk 0.21cvss 4.3epss 0.01

    The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that…

  • CVE-2023-2714MedMay 20, 2023
    risk 0.21cvss 4.3epss 0.01

    The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level…