Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2024-10-17 CVE-2024-9215 The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the 'authors-user_id' user controlled key.
network
low complexity
CWE-639
8.8
2024-10-17 CVE-2024-9862 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0.
network
low complexity
CWE-639
critical
9.8
2024-10-16 CVE-2023-7286 The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2.
network
low complexity
CWE-639
6.5
2024-10-15 CVE-2024-49388 Authorization Bypass Through User-Controlled Key vulnerability in Acronis Cyber Protect 16
Sensitive information manipulation due to improper authorization.
network
low complexity
acronis CWE-639
critical
9.1
2024-10-15 CVE-2024-9687 Authorization Bypass Through User-Controlled Key vulnerability in Dueclic WP 2FA With Telegram
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.
network
low complexity
dueclic CWE-639
8.8
2024-10-04 CVE-2024-47657 Authorization Bypass Through User-Controlled Key vulnerability in Shilpisoft NET Back Office
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints.
network
low complexity
shilpisoft CWE-639
6.5
2024-10-02 CVE-2024-20513 Authorization Bypass Through User-Controlled Key vulnerability in Cisco products
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for handlers that are used during SSL VPN session establishment.
network
low complexity
cisco CWE-639
5.3
2024-09-28 CVE-2024-9298 Authorization Bypass Through User-Controlled Key vulnerability in Oretnom23 Railway Reservation System 1.0
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0.
network
low complexity
oretnom23 CWE-639
4.3
2024-09-25 CVE-2024-8290 Authorization Bypass Through User-Controlled Key vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key.
network
low complexity
wclovers CWE-639
8.8
2024-09-25 CVE-2024-8485 Authorization Bypass Through User-Controlled Key vulnerability in Jianbo Rest API to Miniprogram
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated.
network
low complexity
jianbo CWE-639
critical
9.8