Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2022-23180 Missing Authorization vulnerability in Themehunk Contact Form & Lead Form Elementor Builder
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
network
low complexity
themehunk CWE-862
4.3
2024-01-16 CVE-2024-0235 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0236 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0237 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0238 Missing Authorization vulnerability in Myeventon Eventon
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
network
low complexity
myeventon CWE-862
6.1
2024-01-16 CVE-2024-0570 Missing Authorization vulnerability in Totolink N350Rt Firmware 9.3.5U.6265
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265.
network
low complexity
totolink CWE-862
critical
9.1
2024-01-16 CVE-2024-0569 Missing Authorization vulnerability in Totolink T8 Firmware 4.1.5Cu.83320220905
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905.
network
low complexity
totolink CWE-862
critical
9.1
2024-01-16 CVE-2023-34063 Missing Authorization vulnerability in VMWare Aria Automation and Cloud Foundation
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
network
low complexity
vmware CWE-862
8.3
2024-01-15 CVE-2023-5905 Missing Authorization vulnerability in Demomentsomtres Export Posts With Images
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.
network
low complexity
demomentsomtres CWE-862
8.1
2024-01-15 CVE-2023-6029 Missing Authorization vulnerability in Spider-Themes Eazydocs
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
network
low complexity
spider-themes CWE-862
7.5