Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-8675 The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.2.
network
low complexity
CWE-862
4.3
2024-09-28 CVE-2024-9297 Missing Authorization vulnerability in Oretnom23 Railway Reservation System 1.0
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0.
network
low complexity
oretnom23 CWE-862
6.3
2024-09-28 CVE-2024-9189 Missing Authorization vulnerability in Wpfactory Eu/Uk VAT Manager for Woocommerce
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12.
network
low complexity
wpfactory CWE-862
5.3
2024-09-27 CVE-2024-9202 Missing Authorization vulnerability in Eclipse Dataspace Components
In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to request a single dataset, which should be subject to the same filtering process, but currently is missing the correct filtering. This enables parties to potentially see datasets they should not have access to, thereby exposing sensitive information.
network
high complexity
eclipse CWE-862
5.3
2024-09-26 CVE-2024-8771 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34.
network
low complexity
CWE-862
4.3
2024-09-26 CVE-2024-9025 Missing Authorization vulnerability in Codesupply Sight
The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2.
network
low complexity
codesupply CWE-862
5.3
2024-09-26 CVE-2024-47330 Missing Authorization vulnerability in Supsystic Slider and Social Share Buttons
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
network
low complexity
supsystic CWE-862
8.8
2024-09-26 CVE-2024-8552 Missing Authorization vulnerability in Wpchill Download Monitor
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9.
network
low complexity
wpchill CWE-862
4.3
2024-09-25 CVE-2024-8678 Missing Authorization vulnerability in Revolut Gateway for Woocommerce
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3.
network
low complexity
revolut CWE-862
5.3
2024-09-25 CVE-2024-6845 Missing Authorization vulnerability in Smartsearchwp
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
network
low complexity
smartsearchwp CWE-862
5.3