VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 450 of 463
  • CVE-2026-12557MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-12729MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the…

  • CVE-2026-59097MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can…

  • CVE-2026-57760MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

  • CVE-2026-57750MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

  • CVE-2026-57746HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Broken Access Control in Booked <= 3.0.0 versions.

  • CVE-2026-57731MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Broken Access Control in Flatsome <= 3.20.5 versions.

  • CVE-2026-57730MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

  • CVE-2026-57689MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.

  • CVE-2026-57688HigJul 2, 2026
    risk 0.00cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

  • CVE-2026-57685MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.

  • CVE-2026-57669MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.

  • CVE-2026-57355MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

  • CVE-2026-57353MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

  • CVE-2026-39448HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.

  • CVE-2026-27433MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.

  • CVE-2025-69134HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.

  • CVE-2025-66076MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.

  • CVE-2026-13459MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-12472MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…