VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 435 of 464
  • CVE-2026-66751MedJul 28, 2026
    risk 0.00cvss 5.4epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms…

  • CVE-2026-66750MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval…

  • CVE-2026-16774MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and…

  • CVE-2026-15411MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-15025HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.01

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch,…

  • CVE-2026-13110MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and…

  • CVE-2026-14168HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

  • CVE-2026-16587MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-14924HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

  • CVE-2026-14821LowJul 28, 2026
    risk 0.00cvss 2.7epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

  • CVE-2026-12124MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST…

  • CVE-2026-66473HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

  • CVE-2026-65445MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

  • CVE-2026-43665MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

  • CVE-2026-65922HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level;…

  • CVE-2026-66477MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

  • CVE-2026-66442MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

  • CVE-2026-65568MedJul 27, 2026
    risk 0.00cvss 5.0epss 0.00

    Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

  • CVE-2026-65567MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

  • CVE-2026-65435MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.