VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (4,575)

page 60 of 229
  • CVE-2024-56295MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= 5.5.6.

  • CVE-2024-11929MedJan 9, 2025
    risk 0.42cvss 6.4epss 0.00

    The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2024-56294MedJan 7, 2025
    risk 0.42cvss 6.4epss 0.00

    Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nexter Blocks: from n/a through <= 4.0.7.

  • CVE-2024-11496MedJan 7, 2025
    risk 0.42cvss 6.5epss 0.00

    The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin options and potentially break the site.

  • CVE-2023-45633MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a through 2.6.2.

  • CVE-2023-40327MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.

  • CVE-2023-47689MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Toast Plugins Animator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animator: from n/a through 3.0.10.

  • CVE-2023-47180MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Finale Lite: from n/a through 2.16.0.

  • CVE-2023-46644MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WP CTA PRO WordPress CTA allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through 1.5.8.

  • CVE-2023-46631MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce product-recommendation-quiz-for-ecommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through <= 2.1.2.

  • CVE-2023-46610MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Mohamed Magdy Quill Forms quillforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through <= 3.3.0.

  • CVE-2023-46609MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in FeedFocal FeedFocal feedfocal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FeedFocal: from n/a through <= 1.2.2.

  • CVE-2023-46195MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in CoSchedule Headline Analyzer headline-analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headline Analyzer: from n/a through <= 1.3.1.

  • CVE-2023-45275MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28.

  • CVE-2024-56002MedDec 31, 2024
    risk 0.42cvss 6.4epss 0.00

    Missing Authorization vulnerability in mightyforms Contact Form, Survey & Form Builder – MightyForms mightyforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form, Survey & Form Builder – MightyForms: from n/a through <= 1.3.9.

  • CVE-2024-55995MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Torod Company for Information Technology Torod torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through <= 1.7.

  • CVE-2024-56031MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Yulio Aleman Jimenez Smart Shopify Product smart-shopify-product allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Shopify Product: from n/a through <= 1.0.2.

  • CVE-2024-55991MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.2.9.1.

  • CVE-2024-12266MedDec 24, 2024
    risk 0.42cvss 6.5epss 0.00

    The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the elex_dp_export_rules() and elex_dp_import_rules() functions in all versions up to, and including, 2.1.7. This makes it possible for unauthenticated attackers to import and export product rules along with obtaining phpinfo() data

  • CVE-2024-55997MedDec 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery & Pickup Location Date Time: from n/a through <= 1.1.0.