Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-11-22 CVE-2024-11104 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in all versions up to, and including, 2.6.2.
network
low complexity
CWE-862
8.1
2024-11-22 CVE-2024-11355 The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3.
network
low complexity
CWE-862
4.3
2024-11-22 CVE-2024-11601 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1.
network
low complexity
CWE-862
8.1
2024-11-21 CVE-2024-10528 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, and including, 2.8.9.
network
low complexity
CWE-862
4.3
2024-11-21 CVE-2024-10532 The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all versions up to, and including, 1.2.7.
network
low complexity
CWE-862
4.3
2024-11-21 CVE-2024-11334 Missing Authorization vulnerability in Nes360 MY Contador Lesr
The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0.
network
low complexity
nes360 CWE-862
5.3
2024-11-21 CVE-2024-11354 Missing Authorization vulnerability in Codelizar Ultimate Youtube Video & Shorts Player With Vimeo
The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3.
network
low complexity
codelizar CWE-862
4.3
2024-11-20 CVE-2024-10665 The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check on the yaadpay_view_log_callback() and yaadpay_delete_log_callback() functions in all versions up to, and including, 2.2.4.
network
low complexity
CWE-862
5.4
2024-11-20 CVE-2024-10900 Missing Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6.
network
low complexity
metagauss CWE-862
8.1
2024-11-18 CVE-2024-10390 The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0.
network
low complexity
CWE-862
6.4