VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 436 of 464
  • CVE-2026-65433MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.

  • CVE-2026-59560MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

  • CVE-2026-59557MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

  • CVE-2026-59536HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

  • CVE-2026-59535HigJul 27, 2026
    risk 0.00cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

  • CVE-2026-59534HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

  • CVE-2026-59530HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

  • CVE-2026-59529HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

  • CVE-2026-13390MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as…

  • CVE-2026-66012CriJul 25, 2026
    risk 0.00cvss 10.0epss 0.00

    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with…

  • CVE-2026-66027HigJul 24, 2026
    risk 0.00cvss 8.3epss 0.00

    Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read…

  • CVE-2026-16799MedJul 24, 2026
    risk 0.00cvss 5.0epss 0.00

    Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization…

  • CVE-2026-10033HigJul 24, 2026
    risk 0.00cvss 7.3epss 0.00

    The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers…

  • CVE-2026-12654MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-12690LowJul 24, 2026
    risk 0.00cvss 3.8epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's…

  • CVE-2026-12689MedJul 24, 2026
    risk 0.00cvss 5.4epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read…

  • CVE-2026-11354MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and…

  • CVE-2026-47755MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the…

  • CVE-2026-65916HigJul 23, 2026
    risk 0.00cvss 8.1epss 0.00

    CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary…

  • CVE-2026-65895HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable…