VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 451 of 463
  • CVE-2026-12134MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-12122MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full…

  • CVE-2026-11600MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The…

  • CVE-2026-11592MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-57721MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.

  • CVE-2026-57720MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.

  • CVE-2026-27409MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.

  • CVE-2026-23537CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.01

    A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can…

  • CVE-2026-27435MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

  • CVE-2026-12435MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-1239HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes…

  • CVE-2026-13468HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-12902MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12133MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX…

  • CVE-2026-12113MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above,…

  • CVE-2026-58448MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the…

  • CVE-2026-9132MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a…

  • CVE-2026-58377HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController…

  • CVE-2026-58373MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the…

  • CVE-2026-58176MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated…