VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (4,593)

page 98 of 230
  • CVE-2024-2017MedJun 6, 2024
    risk 0.35cvss 5.4epss 0.00

    The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject PHP Objects and modify the status of countdowns.

  • CVE-2024-4997MedJun 4, 2024
    risk 0.35cvss 5.3epss 0.01

    The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages.

  • CVE-2024-1324MedJun 1, 2024
    risk 0.35cvss 5.3epss 0.01

    The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function hooked via a norpriv AJAX in all versions up to, and including, 1.9.8. This makes it possible for unauthenticated attackers to retrieve the contents of arbitrary posts that may not be public.

  • CVE-2023-6325MedMay 23, 2024
    risk 0.35cvss 5.3epss 0.01

    The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata.

  • CVE-2024-4444MedMay 14, 2024
    risk 0.35cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

  • CVE-2024-1229MedMay 14, 2024
    risk 0.35cvss 5.3epss 0.01

    The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.

  • CVE-2024-3237MedMay 4, 2024
    risk 0.35cvss 5.4epss 0.00

    The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to true.

  • CVE-2024-3585MedMay 2, 2024
    risk 0.35cvss 5.3epss 0.01

    The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on the hooks function in all versions up to, and including, 1.0.2.3. This makes it possible for unauthenticated attackers to download information about contact form entries with PDFs.

  • CVE-2024-3312MedMay 2, 2024
    risk 0.35cvss 5.3epss 0.01

    The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts.

  • CVE-2024-1809MedMay 2, 2024
    risk 0.35cvss 5.4epss 0.00

    The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.

  • CVE-2024-1688MedMay 2, 2024
    risk 0.35cvss 5.3epss 0.01

    The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.

  • CVE-2024-33588MedApr 29, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.

  • CVE-2024-33636MedApr 29, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.

  • CVE-2022-40975MedApr 26, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7.

  • CVE-2024-32142MedApr 18, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Ovic Team Ovic Responsive WPBakery.This issue affects Ovic Responsive WPBakery: from n/a through 1.3.0.

  • CVE-2024-32515MedApr 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Qamar Sheeraz, Nasir Ahmad Mega Addons For Elementor.This issue affects Mega Addons For Elementor: from n/a through 1.8.

  • CVE-2024-27970MedApr 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in BogdanFix WP SendFox.This issue affects WP SendFox: from n/a through 1.3.0.

  • CVE-2024-25922MedApr 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9.

  • CVE-2024-25907MedApr 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

  • CVE-2023-27607MedApr 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.