CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 50 of 126
- CVE-2024-0358MEDIUMCVSS 5.3EG 5.32024-01-10
A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. The manipulation leads to improper access controls. It is possible to initiate the a…
- CVE-2024-0366MEDIUMCVSS 4.3EG 4.32024-02-05
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This m…
- CVE-2024-0369MEDIUMCVSS 4.3EG 4.32024-03-13
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This makes it possible fo…
- CVE-2024-0370MEDIUMCVSS 4.3EG 4.32024-02-05
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_view' function in all versions up to, and…
- CVE-2024-0371MEDIUMCVSS 4.3EG 4.32024-02-05
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'create_view' function in all versions up to, a…
- CVE-2024-0373MEDIUMCVSS 4.3EG 4.32024-02-05
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validati…
- CVE-2024-0374MEDIUMCVSS 4.3EG 4.32024-02-05
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validati…
- CVE-2024-0377MEDIUMCVSS 5.3EG 5.32024-03-13
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. Th…
- CVE-2024-0410HIGHCVSS 7.7EG 7.72024-02-22
An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
- CVE-2024-0411MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper acces…
- CVE-2024-0412MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to impro…
- CVE-2024-0413MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file public/install.php. The manipulation leads to improper access controls. The attack may be init…
- CVE-2024-0414MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the att…
- CVE-2024-0415MEDIUMCVSS 6.3EG 6.32024-01-11
A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The man…
- CVE-2024-0434MEDIUMCVSS 5.3EG 5.32024-05-29
The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to…
- CVE-2024-0437MEDIUMCVSS 4.3EG 4.32024-05-15
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it pos…
- CVE-2024-0451MEDIUMCVSS 5.0EG 5.02024-05-22
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authentica…
- CVE-2024-0452MEDIUMCVSS 5.0EG 5.02024-05-22
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for au…
- CVE-2024-0453MEDIUMCVSS 5.0EG 5.02024-05-22
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for au…
- CVE-2024-0551HIGHCVSS 7.1EG 7.12024-02-27
Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that the deterministic n…
- CVE-2024-0570HIGHCVSS 7.3EG 7.32024-01-16
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improper access controls.…
- CVE-2024-0626MEDIUMCVSS 5.3EG 5.32024-04-09
The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it po…
- CVE-2024-0631MEDIUMCVSS 5.3EG 5.32024-03-13
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. This makes it possible…
- CVE-2024-0642CRITICALCVSS 9.8EG 9.82024-01-17
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper …
- CVE-2024-0687MEDIUMCVSS 5.3EG 5.32024-03-13
The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obt…
- CVE-2024-0712HIGHCVSS 7.3EG 7.32024-01-19
A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of the file /useratte/inc/userattea.php. The manipulation leads to improper access controls. …
- CVE-2024-0766MEDIUMCVSS 4.3EG 4.32024-02-28
The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including,…
- CVE-2024-0795HIGHCVSS 7.2EG 7.22024-03-02
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have…
- CVE-2024-0810MEDIUMCVSS 4.3EG 4.32024-01-24
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security seve…
- CVE-2024-0899MEDIUMCVSS 5.3EG 5.32024-04-09
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via th…
- CVE-2024-0965MEDIUMCVSS 5.3EG 5.32024-02-08
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugi…
- CVE-2024-0969MEDIUMCVSS 5.3EG 5.32024-02-05
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restricti…
- CVE-2024-0972MEDIUMCVSS 5.3EG 5.32024-06-06
The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All…
- CVE-2024-0975MEDIUMCVSS 5.3EG 5.32024-02-28
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "…
- CVE-2024-0978MEDIUMCVSS 5.3EG 5.32024-02-29
The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privac…
- CVE-2024-1011MEDIUMCVSS 4.3EG 4.32024-01-29
A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component Leave Handler. The manipulation of the argument id …
- CVE-2024-10124CRITICALCVSS 9.8EG 9.82024-12-12
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions…
- CVE-2024-10241MEDIUMCVSS 4.3EG 4.32024-10-29
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
- CVE-2024-10272HIGHCVSS 7.5EG 7.52025-03-20
lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the /v1/datasets endpoint without a valid authoriz…
- CVE-2024-10275HIGHCVSS 7.3EG 7.32025-03-20
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a priv…
- CVE-2024-10330MEDIUMCVSS 6.5EG 6.52025-03-20
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users…
- CVE-2024-10353MEDIUMCVSS 6.3EG 6.32024-10-25
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the …
- CVE-2024-10363MEDIUMCVSS 5.4EG 5.42025-03-20
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowin…
- CVE-2024-10366HIGHCVSS 6.5EG 7.62025-03-20
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowi…
- CVE-2024-10393MEDIUMCVSS 5.3EG 5.32024-11-21
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes i…
- CVE-2024-1044MEDIUMCVSS 5.3EG 5.32024-02-29
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it pos…
- CVE-2024-1053MEDIUMCVSS 4.3EG 4.32024-02-22
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authentica…
- CVE-2024-10764MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. I…
- CVE-2024-10765MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted u…
- CVE-2024-10766MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →