Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-7856 Missing Authorization vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1.
network
low complexity
sonaar CWE-862
8.1
2024-08-29 CVE-2024-41918 Missing Authorization vulnerability in Rakuten Ichiba
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme.
network
low complexity
rakuten CWE-862
6.1
2024-08-28 CVE-2024-45058 Missing Authorization vulnerability in Portabilis I-Educar
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers.
network
low complexity
portabilis CWE-862
8.1
2024-08-28 CVE-2024-8195 Missing Authorization vulnerability in Permalink Manager Lite Project Permalink Manager Lite
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4.
network
low complexity
permalink-manager-lite-project CWE-862
5.3
2024-08-28 CVE-2024-7447 Missing Authorization vulnerability in Funnelforms Free
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in all versions up to, and including, 3.7.3.2.
network
low complexity
funnelforms CWE-862
5.3
2024-08-27 CVE-2024-8199 Missing Authorization vulnerability in Smashballoon Reviews Feed
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all versions up to, and including, 1.1.2.
network
low complexity
smashballoon CWE-862
4.3
2024-08-26 CVE-2024-43214 Missing Authorization vulnerability in Mycred
Missing Authorization vulnerability in myCred.This issue affects myCred: from n/a through 2.7.2.
network
low complexity
mycred CWE-862
5.3
2024-08-24 CVE-2024-6631 Missing Authorization vulnerability in Imagerecycle PDF & Image Compression
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14.
network
low complexity
imagerecycle CWE-862
4.3
2024-08-23 CVE-2024-7258 Missing Authorization vulnerability in Wpmarketingrobot Woocommerce Google Feed Manager
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and including, 2.8.0.
network
low complexity
wpmarketingrobot CWE-862
8.8
2024-08-21 CVE-2024-7030 Missing Authorization vulnerability in Zaytech Smart Online Order for Clover
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6.
network
low complexity
zaytech CWE-862
4.3