Vulnerabilities > Missing Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-07 | CVE-2019-25142 | Missing Authorization vulnerability in Extendthemes Materialis and Mesmerize The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). | 8.8 |
2023-06-07 | CVE-2019-25143 | Missing Authorization vulnerability in Mooveagency Gdpr Cookie Compliance The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. | 4.3 |
2023-06-07 | CVE-2020-36696 | Missing Authorization vulnerability in Tychesoftwares Product Input Fields for Woocommerce The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. | 7.5 |
2023-06-07 | CVE-2020-36697 | Missing Authorization vulnerability in Appsaloon WP Gdpr The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. | 6.5 |
2023-06-07 | CVE-2020-36699 | Missing Authorization vulnerability in Quick Page/Post Redirect Project Quick Page/Post Redirect The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. | 4.3 |
2023-06-07 | CVE-2020-36702 | Missing Authorization vulnerability in Brainstormforce Spectra The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. | 4.3 |
2023-06-07 | CVE-2020-36712 | Missing Authorization vulnerability in Kaliforms Kali Forms The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. | 5.3 |
2023-06-07 | CVE-2020-36715 | Missing Authorization vulnerability in Xootix Login/Signup Popup The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. | 4.6 |
2023-06-07 | CVE-2020-36716 | Missing Authorization vulnerability in Wpwhitesecurity WP Activity LOG The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. | 7.3 |
2023-06-07 | CVE-2020-36719 | Missing Authorization vulnerability in Cridio Listingpro The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. | 9.8 |