VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 433 of 464
  • CVE-2026-70439MedAug 5, 2026
    risk 0.00cvss 6.5epss 0.00

    Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.

  • CVE-2026-16605HigAug 5, 2026
    risk 0.00cvss 7.2epss 0.00

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on…

  • CVE-2026-16561HigAug 5, 2026
    risk 0.00cvss 7.5epss 0.00

    The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.

  • CVE-2026-18650HigAug 4, 2026
    risk 0.00cvss 8.8epss 0.00

    Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

  • CVE-2026-17070HigAug 4, 2026
    risk 0.00cvss 8.8epss 0.00

    Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

  • CVE-2026-16546MedAug 4, 2026
    risk 0.00cvss 4.3epss 0.00

    The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary…

  • CVE-2026-16056MedAug 4, 2026
    risk 0.00cvss 4.3epss 0.00

    The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

  • CVE-2026-16035MedAug 4, 2026
    risk 0.00cvss 4.3epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients…

  • CVE-2026-15958CriAug 4, 2026
    risk 0.00cvss 9.3epss 0.00

    The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary…

  • CVE-2026-16300CriAug 3, 2026
    risk 0.00cvss 9.8epss 0.00

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-16289MedAug 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any…

  • CVE-2026-16276LowAug 3, 2026
    risk 0.00cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators…

  • CVE-2026-16274LowAug 3, 2026
    risk 0.00cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site…

  • CVE-2026-16057MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts,…

  • CVE-2026-15930CriAug 3, 2026
    risk 0.00cvss 9.4epss 0.00

    The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data…

  • CVE-2026-16285HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric…

  • CVE-2026-16042MedAug 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

  • CVE-2026-13389MedAug 2, 2026
    risk 0.00cvss 6.5epss 0.00

    The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent…

  • CVE-2026-15227MedJul 31, 2026
    risk 0.00cvss epss 0.00

    Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • CVE-2026-14930HigJul 31, 2026
    risk 0.00cvss 7.5epss 0.00

    The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions)…