VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 71 of 464
  • CVE-2025-5117HigMay 27, 2025
    risk 0.50cvss 8.8epss 0.00

    The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above,…

  • CVE-2025-43011HigMay 13, 2025
    risk 0.50cvss 7.7epss 0.00

    Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the…

  • CVE-2025-2807HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it…

  • CVE-2025-27428HigApr 8, 2025
    risk 0.50cvss 7.7epss 0.01

    Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high…

  • CVE-2025-2075HigApr 4, 2025
    risk 0.50cvss 8.8epss 0.02

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks…

  • CVE-2025-1657HigMar 15, 2025
    risk 0.50cvss 8.8epss 0.00

    The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it…

  • CVE-2025-1309HigMar 7, 2025
    risk 0.50cvss 8.8epss 0.00

    The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() function in all versions up…

  • CVE-2024-12544HigMar 1, 2025
    risk 0.50cvss 8.8epss 0.01

    The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions…

  • CVE-2024-12171HigFeb 1, 2025
    risk 0.50cvss 8.8epss 0.00

    The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for authenticated…

  • CVE-2024-10591HigJan 30, 2025
    risk 0.50cvss 8.8epss 0.00

    The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hubwoo_save_updates()…

  • CVE-2024-11271HigJan 8, 2025
    risk 0.50cvss 8.8epss 0.00

    The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with…

  • CVE-2024-11270HigJan 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible…

  • CVE-2024-11725HigJan 7, 2025
    risk 0.50cvss 8.8epss 0.01

    The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including,…

  • CVE-2024-56067HigDec 31, 2024
    risk 0.50cvss 7.5epss 0.10

    Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

  • CVE-2024-11643HigDec 4, 2024
    risk 0.50cvss 8.8epss 0.01

    The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This…

  • CVE-2024-11194HigNov 19, 2024
    risk 0.50cvss 8.8epss 0.01

    The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and…

  • CVE-2022-31666HigNov 14, 2024
    risk 0.50cvss 7.7epss 0.01

    Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

  • CVE-2024-49357HigOct 24, 2024
    risk 0.50cvss 7.5epss 0.24

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http:///v1/users/image?path=/var/lib/casaos/1/app_order.json` and…

  • CVE-2024-49657HigOct 23, 2024
    risk 0.50cvss 7.7epss 0.00

    Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.

  • CVE-2024-8480HigSep 6, 2024
    risk 0.50cvss 8.8epss 0.01

    The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for…