VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (4,588)

page 82 of 230
  • CVE-2025-62960MedDec 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Light: from n/a through <= 1.6.7.

  • CVE-2025-68088MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Huger for Elementor: from n/a through <= 1.1.5.

  • CVE-2025-68087MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modalier for Elementor: from n/a through <= 1.0.6.

  • CVE-2025-68086MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reformer for Elementor: from n/a through <= 1.0.6.

  • CVE-2025-68085MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Buttoner for Elementor: from n/a through <= 1.0.6.

  • CVE-2025-68084MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Auction : from n/a through <= 4.3.3.

  • CVE-2025-66167MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Lottier lottier-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier: from n/a through <= 1.1.1.

  • CVE-2025-66166MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Lottier for Elementor lottier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier for Elementor: from n/a through <= 1.0.9.

  • CVE-2025-66165MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Lottier for WPBakery lottier-wpbakery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lottier for WPBakery: from n/a through <= 1.1.7.

  • CVE-2025-66164MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

  • CVE-2025-66163MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masker for Elementor: from n/a through <= 1.1.4.

  • CVE-2025-66162MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Spoter for Elementor spoter-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spoter for Elementor: from n/a through <= 1.04.

  • CVE-2025-66161MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grider for Elementor: from n/a through <= 1.0.8.

  • CVE-2025-66147MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in merkulove Coder for Elementor coder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coder for Elementor: from n/a through <= 1.0.13.

  • CVE-2025-66134MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FileBird Pro: from n/a through <= 6.5.1.

  • CVE-2025-13956MedDec 16, 2025
    risk 0.35cvss 5.3epss 0.03

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total revenue summaries and order status counts

  • CVE-2025-14446MedDec 13, 2025
    risk 0.35cvss 5.4epss 0.00

    The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the easynotify_cp_reset() function in all versions up to, and including, 1.1.37. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset plugin settings to their default values.

  • CVE-2025-14064MedDec 12, 2025
    risk 0.35cvss 5.4epss 0.00

    The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view, create, modify, and delete task boards belonging to any BuddyPress group, including private and hidden groups they are not members of.

  • CVE-2023-23729MedDec 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

  • CVE-2025-67562MedDec 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WebCodingPlace Image Caption Hover Pro image-caption-hover-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Caption Hover Pro: from n/a through < 20.0.