VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 46 of 464
  • CVE-2025-26368HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups via crafted HTTP requests.

  • CVE-2024-13800HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.00

    The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for…

  • CVE-2024-13656HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.00

    The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and…

  • CVE-2024-13654HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.00

    The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. This…

  • CVE-2025-25167HigFeb 7, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.

  • CVE-2024-13767HigJan 31, 2025
    risk 0.53cvss 8.1epss 0.01

    The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2025-21396HigJan 29, 2025
    risk 0.53cvss 8.2epss 0.01

    Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-23477HigJan 21, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Realty Workstation: from n/a through <= 1.0.45.

  • CVE-2024-46450HigJan 16, 2025
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.

  • CVE-2024-54359HigDec 16, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Banner System: from n/a through <= 1.0.0.

  • CVE-2023-41130HigDec 13, 2024
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.12.

  • CVE-2024-10783HigDec 13, 2024
    risk 0.53cvss 8.1epss 0.02

    The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in…

  • CVE-2023-49856HigDec 9, 2024
    risk 0.53cvss 8.1epss 0.01

    Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through <= 2.6.84.

  • CVE-2023-49817HigDec 9, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1.

  • CVE-2023-48286HigDec 9, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing Authorization vulnerability in mra13 Stripe Payments stripe-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through <= 2.0.79.

  • CVE-2024-42453HigDec 4, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially…

  • CVE-2024-8114HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

  • CVE-2024-11601HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.00

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to…

  • CVE-2024-11104HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check…

  • CVE-2024-10728HigNov 16, 2024
    risk 0.53cvss 8.8epss 0.36

    The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16.…