CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 26 of 126
- CVE-2021-24730MEDIUMCVSS 4.3EG 4.32022-02-28
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description…
- CVE-2021-24733MEDIUMCVSS 4.3EG 4.32022-01-24
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.
- CVE-2021-24742MEDIUMCVSS 6.5EG 6.52021-11-01
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
- CVE-2021-24752MEDIUMCVSS 5.7EG 5.72021-10-18
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9…
- CVE-2021-24757MEDIUMCVSS 5.3EG 5.32021-11-01
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload im…
- CVE-2021-24770MEDIUMCVSS 6.5EG 6.52021-11-01
The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbi…
- CVE-2021-24779MEDIUMCVSS 6.5EG 6.52021-10-25
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.
- CVE-2021-24781MEDIUMCVSS 4.3EG 4.32021-11-01
The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)
- CVE-2021-24783MEDIUMCVSS 6.5EG 6.52021-11-08
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
- CVE-2021-24788MEDIUMCVSS 6.5EG 6.52021-11-08
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary ca…
- CVE-2021-24801MEDIUMCVSS 4.3EG 4.32021-11-08
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the S…
- CVE-2021-24816MEDIUMCVSS 4.3EG 4.32021-11-08
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.
- CVE-2021-24824MEDIUMCVSS 4.3EG 4.32022-03-07
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, …
- CVE-2021-24825MEDIUMCVSS 4.3EG 4.32022-03-07
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such…
- CVE-2021-24839HIGHCVSS 7.5EG 7.52022-02-07
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk…
- CVE-2021-24845MEDIUMCVSS 6.5EG 6.52021-12-13
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to c…
- CVE-2021-24853MEDIUMCVSS 4.3EG 4.32021-11-17
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the red…
- CVE-2021-24859MEDIUMCVSS 4.3EG 4.32021-12-13
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulne…
- CVE-2021-24905HIGHCVSS 8.0EG 8.02022-03-21
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to dele…
- CVE-2021-24906HIGHCVSS 7.5EG 7.52022-01-24
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted requ…
- CVE-2021-24916HIGHCVSS 7.5EG 7.52023-08-07
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
- CVE-2021-24993MEDIUMCVSS 6.5EG 6.52022-02-07
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change …
- CVE-2021-25084MEDIUMCVSS 4.3EG 4.32022-02-07
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to cal…
- CVE-2021-25087HIGHCVSS 7.5EG 7.52022-03-07
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as po…
- CVE-2021-25095HIGHCVSS 7.1EG 7.12022-02-07
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block…
- CVE-2021-25097MEDIUMCVSS 6.5EG 6.52022-02-01
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
- CVE-2021-25320CRITICALCVSS 9.9EG 9.92021-07-15
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without furth…
- CVE-2021-25340MEDIUMCVSS 5.1EG 5.12021-03-04
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
- CVE-2021-25349HIGHCVSS 5.5EG 7.82021-03-25
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
- CVE-2021-25359MEDIUMCVSS 4.0EG 4.02021-04-09
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
- CVE-2021-25405MEDIUMCVSS 5.5EG 5.52021-06-11
An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files.
- CVE-2021-25412HIGHCVSS 7.8EG 7.82021-06-11
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
- CVE-2021-25431MEDIUMCVSS 5.5EG 5.52021-07-08
Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer.
- CVE-2021-25438HIGHCVSS 7.8EG 7.82021-07-08
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
- CVE-2021-25439LOWCVSS 3.3EG 3.32021-07-08
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
- CVE-2021-25440HIGHCVSS 7.8EG 7.82021-07-08
Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.
- CVE-2021-25446MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
- CVE-2021-25447MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
- CVE-2021-25448MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
- CVE-2021-25463MEDIUMCVSS 4.0EG 4.02021-09-09
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
- CVE-2021-25501MEDIUMCVSS 5.7EG 5.72021-11-05
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
- CVE-2021-25672HIGHCVSS 8.8EG 8.82021-03-15
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts.
- CVE-2021-25749HIGHCVSS 7.8EG 7.82023-05-24
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
- CVE-2021-25954MEDIUMCVSS 4.3EG 4.32021-08-09
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, t…
- CVE-2021-25956MEDIUMCVSS 4.7EG 4.72021-08-17
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. Thi…
- CVE-2021-25991MEDIUMCVSS 5.7EG 5.72021-12-29
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
- CVE-2021-26118HIGHCVSS 7.5EG 7.52021-01-27
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messag…
- CVE-2021-26334CRITICALCVSS 9.9EG 9.92021-12-01
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
- CVE-2021-26338HIGHCVSS 7.5EG 7.52021-11-16
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
- CVE-2021-26360HIGHCVSS 7.8EG 7.82022-11-09
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead …
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →