VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (4,593)

page 97 of 230
  • CVE-2024-5600MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check and insufficient sanitization on the import_settings() function in all versions up to, and including, 1.3.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject malicious web scripts.

  • CVE-2024-4102MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions like editing pricing tables.

  • CVE-2024-6088MedJul 2, 2024
    risk 0.35cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to create a new account with the default role.

  • CVE-2024-5863MedJun 28, 2024
    risk 0.35cvss 5.4epss 0.00

    The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in all versions up to, and including, 1.13.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to erase all of the content in arbitrary posts.

  • CVE-2024-3627MedJun 20, 2024
    risk 0.35cvss 5.4epss 0.00

    The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts and modify settings.

  • CVE-2023-39310MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

  • CVE-2023-35050MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

  • CVE-2023-40672MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

  • CVE-2024-34815MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.

  • CVE-2024-34804MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.

  • CVE-2024-35663MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0.

  • CVE-2023-52183MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.

  • CVE-2023-52179MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.

  • CVE-2024-4319MedJun 11, 2024
    risk 0.35cvss 5.3epss 0.02

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.

  • CVE-2024-32824MedJun 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2.

  • CVE-2024-32797MedJun 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.

  • CVE-2024-31246MedJun 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 3.2.3.

  • CVE-2024-5607MedJun 7, 2024
    risk 0.35cvss 5.4epss 0.00

    The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings, update page content, send arbitrary emails and inject malicious web scripts.

  • CVE-2023-6876MedJun 7, 2024
    risk 0.35cvss 5.4epss 0.00

    The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clever-fox-activate-theme' function in all versions up to, and including, 25.2.0. This makes it possible for authenticated attackers, with subscriber access and above, to modify the active theme, including to an invalid value which can take down the site.

  • CVE-2024-0972MedJun 6, 2024
    risk 0.35cvss 5.3epss 0.01

    The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be Opened to Guest" feature (when unset) and view restricted page and post content.