VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 434 of 464
  • CVE-2026-14862LowJul 31, 2026
    risk 0.00cvss 3.7epss 0.00

    The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.

  • CVE-2026-14317MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator…

  • CVE-2026-15397HigJul 30, 2026
    risk 0.00cvss 7.2epss 0.00

    The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration…

  • CVE-2026-15252MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from…

  • CVE-2026-15054LowJul 30, 2026
    risk 0.00cvss 3.7epss 0.00

    The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has…

  • CVE-2026-12500HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before…

  • CVE-2026-11867MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary…

  • CVE-2026-14356HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-4672MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were…

  • CVE-2026-14341MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to…

  • CVE-2026-16543HigJul 29, 2026
    risk 0.00cvss epss 0.00

    Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using…

  • CVE-2026-15228HigJul 29, 2026
    risk 0.00cvss epss 0.00

    Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without…

  • CVE-2026-66724MedJul 29, 2026
    risk 0.00cvss epss 0.00

    MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows…

  • CVE-2026-66723HigJul 29, 2026
    risk 0.00cvss epss 0.00

    MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB…

  • CVE-2026-4604MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2026-14488CriJul 29, 2026
    risk 0.00cvss 9.1epss 0.00

    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without…

  • CVE-2026-5626MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2026-17166MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-16184HigJul 28, 2026
    risk 0.00cvss 7.0epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

  • CVE-2026-49258HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not…