Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-08-24 CVE-2024-6631 Missing Authorization vulnerability in Imagerecycle PDF & Image Compression
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14.
network
low complexity
imagerecycle CWE-862
4.3
2024-08-23 CVE-2024-7258 Missing Authorization vulnerability in Wpmarketingrobot Woocommerce Google Feed Manager
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and including, 2.8.0.
network
low complexity
wpmarketingrobot CWE-862
8.8
2024-08-21 CVE-2024-7030 Missing Authorization vulnerability in Zaytech Smart Online Order for Clover
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6.
network
low complexity
zaytech CWE-862
4.3
2024-08-21 CVE-2024-7032 Missing Authorization vulnerability in Zaytech Smart Online Order for Clover
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6.
network
low complexity
zaytech CWE-862
6.5
2024-08-21 CVE-2024-7390 Missing Authorization vulnerability in Starkdigital WP Testimonial Widget
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0.
network
low complexity
starkdigital CWE-862
5.3
2024-08-20 CVE-2024-5939 Missing Authorization vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0.
network
low complexity
givewp CWE-862
5.3
2024-08-20 CVE-2024-5940 Missing Authorization vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0.
network
low complexity
givewp CWE-862
5.3
2024-08-20 CVE-2024-5941 Missing Authorization vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1.
network
low complexity
givewp CWE-862
5.4
2024-08-19 CVE-2024-43401 Missing Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-862
8.0
2024-08-17 CVE-2023-4024 Missing Authorization vulnerability in Softlabbd Radio Player
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73.
network
low complexity
softlabbd CWE-862
5.3