Tag
Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488
1 rule 1 TTP 1 CVEUnauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.
CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability
3 TTPs 1 CVECVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.
CVE-2026-15025: Missing Authorization in Uncanny Automator WordPress Plugin
1 rule 1 TTP 1 CVEA Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.
CVE-2026-14168: ads-tec Industrial IT DVG-IRF Privilege Escalation
1 TTP 1 CVEA high-severity missing authorization vulnerability, CVE-2026-14168, allows a low-privileged remote attacker to escalate privileges to administrator level by exploiting the insert path of the configuration table in ads-tec Industrial IT DVG-IRF series products, ultimately granting full system access.
CVE-2026-65709 - sysPass JSON-RPC API Missing Object-Level Authorization
5 TTPs 3 CVEssysPass versions up to 3.2.11 are affected by a missing object-level authorization vulnerability in the JSON-RPC API. Attackers holding an API token can exploit this flaw by invoking AccountController methods (e.g., viewAction, editAction, deleteAction, editPassAction) without proper AccountFilterUser checks, allowing them to enumerate account metadata, overwrite passwords, and delete user accounts across the entire vault, bypassing per-account access control defined by their token permissions.
Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover
3 TTPs 1 CVEThe Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.
CVE-2026-11340 — Missing Authorization in HAVELSAN Liman MYS
1 TTP 1 CVEA missing authorization vulnerability (CVE-2026-11340) in HAVELSAN Inc. Liman MYS versions prior to release.Master.1107 allows an attacker with low privileges to access functionality not properly constrained by ACLs, leading to high impact on integrity and availability.
CVE-2026-8377: Missing Authorization in Armiya GKS Allows Data Collection
2 TTPs 1 CVEA critical Missing Authorization vulnerability (CVE-2026-8377) in Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 allows an unauthenticated or unauthorized attacker to collect sensitive data from common resource locations, leading to unauthorized information disclosure.
Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability
2 rules 2 TTPsPimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.
Funnel Builder for WooCommerce Checkout Missing Authorization Vulnerability (CVE-2026-47100)
2 rules 1 CVEFunnel Builder for WooCommerce Checkout versions prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and inject malicious JavaScript, impacting checkout page visitors.
Bitwarden Server Missing Authorization Vulnerability Leading to Organization Takeover (CVE-2026-43639)
2 rules 1 TTP 1 CVEBitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability (CVE-2026-43639) that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization in cloud-hosted deployments.
WeKan Missing Authorization Vulnerability in Integration REST API
2 rules 1 TTP 1 CVEWeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints, allowing authenticated board members to perform administrative actions without proper privilege verification, potentially leading to unauthorized data access and modification.
Gravity SMTP Plugin Missing Authorization Vulnerability (CVE-2026-4162)
2 rules 1 TTP 1 CVEThe Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access or higher to uninstall/deactivate the plugin and delete plugin options, and is also exploitable via Cross-Site Request Forgery.
SimpleHelp Missing Authorization Vulnerability Leads to Privilege Escalation
2 rules 1 TTP 1 CVEA missing authorization vulnerability in SimpleHelp (CVE-2024-57726) allows low-privileged technicians to create API keys with excessive permissions, potentially escalating privileges to the server admin role.
Vertex Addons for Elementor WordPress Plugin Missing Authorization Vulnerability (CVE-2026-4326)
2 rules 1 TTP 1 CVEThe Vertex Addons for Elementor plugin for WordPress up to version 1.6.4 is vulnerable to missing authorization, allowing authenticated attackers with subscriber-level access to install and activate arbitrary plugins.
Geeky Bot WordPress Plugin Missing Authorization Vulnerability Leads to Remote Code Execution
2 rules 3 TTPs 1 CVEThe Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to 1.2.2, allowing unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution by exploiting a nopriv AJAX route and uploading malicious ZIP files.