CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 12 of 43
- CVE-2023-51141MEDIUMCVSS 6.5EG 6.52024-04-11
An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component
- CVE-2023-51502CRITICALCVSS 9.8EG 9.82024-01-05
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
- CVE-2023-51503HIGHCVSS 7.5EG 7.52023-12-31
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from…
- CVE-2023-53914CRITICALCVSS 9.8EG 9.82025-12-17
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpo…
- CVE-2023-53930CRITICALCVSS 7.5EG 9.82025-12-17
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changi…
- CVE-2023-53955CRITICALCVSS 9.8EG 9.82025-12-22
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-su…
- CVE-2023-5544MEDIUMCVSS 5.4EG 5.42023-11-09
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
- CVE-2023-6144CRITICALCVSS 4.8EG 9.12023-11-21
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
- CVE-2023-6223MEDIUMCVSS 4.3EG 4.32024-01-11
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlle…
- CVE-2023-6226MEDIUMCVSS 4.3EG 4.32023-11-28
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled…
- CVE-2023-6317HIGHCVSS 7.2EG 7.22024-04-09
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.…
- CVE-2023-6341MEDIUMCVSS 5.3EG 5.32023-11-30
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a spec…
- CVE-2023-6384MEDIUMCVSS 4.3EG 4.32024-01-22
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
- CVE-2023-6504MEDIUMCVSS 4.3EG 4.32024-01-11
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler funct…
- CVE-2023-6506MEDIUMCVSS 4.3EG 4.32024-01-11
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user c…
- CVE-2023-6515HIGHCVSS 8.8EG 8.82024-02-08
Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-MED: before 1.0.7.
- CVE-2023-6523HIGHCVSS 8.8EG 8.82024-04-05
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XDS: before 3914.
- CVE-2023-6630MEDIUMCVSS 4.3EG 4.32024-01-11
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missin…
- CVE-2023-6724HIGHCVSS 8.8EG 8.82024-02-09
Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before f…
- CVE-2023-6824MEDIUMCVSS 6.5EG 6.52024-01-16
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.
- CVE-2023-6875CRITICALCVSS 9.8EG 9.82024-01-11
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app …
- CVE-2023-6897MEDIUMCVSS 4.3EG 4.32024-04-18
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. …
- CVE-2023-6929CRITICALCVSS 9.8EG 9.82023-12-19
EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attacker…
- CVE-2023-6969MEDIUMCVSS 4.3EG 5.32024-03-13
The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the user_meta shortcode due to missing validation on a user controlled key. This makes it possi…
- CVE-2023-6983MEDIUMCVSS 4.3EG 4.32024-02-05
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing …
- CVE-2023-7031MEDIUMCVSS 5.7EG 5.72024-01-17
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x,…
- CVE-2023-7049MEDIUMCVSS 4.3EG 4.32024-08-16
The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 via the the 'cm_fieldshow' shortcode due to missing validation on the 'job_id' user contro…
- CVE-2023-7198MEDIUMCVSS 4.3EG 4.32024-02-27
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses…
- CVE-2023-7199MEDIUMCVSS 5.3EG 5.32024-01-29
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
- CVE-2023-7286MEDIUMCVSS 6.5EG 6.52024-10-16
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other us…
- CVE-2024-0264CRITICALCVSS 9.8EG 9.82024-01-07
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to author…
- CVE-2024-0366MEDIUMCVSS 4.3EG 4.32024-02-05
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This m…
- CVE-2024-0421MEDIUMCVSS 5.3EG 5.32024-02-12
The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.
- CVE-2024-0580MEDIUMCVSS 6.5EG 6.52024-01-18
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API by making a request to the parameter '/qsige.locato…
- CVE-2024-0839MEDIUMCVSS 5.3EG 5.32024-03-13
The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticate…
- CVE-2024-0872MEDIUMCVSS 4.3EG 4.32024-04-09
The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level acce…
- CVE-2024-10121HIGHCVSS 7.3EG 7.32024-10-18
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../ leads to authorization bypass. The atta…
- CVE-2024-10174HIGHCVSS 7.3EG 7.32024-11-13
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstr…
- CVE-2024-10215CRITICALCVSS 9.8EG 9.82025-01-09
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and acces…
- CVE-2024-10366HIGHCVSS 6.5EG 7.62025-03-20
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowi…
- CVE-2024-10439MEDIUMCVSS 5.3EG 5.32024-10-28
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
- CVE-2024-10452LOWCVSS 2.2EG 2.22024-10-29
Organization admins can delete pending invites created in an organization they are not part of.
- CVE-2024-10497HIGHCVSS 8.8EG 8.82025-01-17
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HT…
- CVE-2024-10654MEDIUMCVSS 5.3EG 5.32024-11-01
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the in…
- CVE-2024-10666MEDIUMCVSS 4.3EG 4.32024-11-22
The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.6 via the [etf] shortcode. This makes it possible for authenticated attackers, with …
- CVE-2024-10667MEDIUMCVSS 4.3EG 4.32024-11-09
The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1.5 via the [csb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible…
- CVE-2024-10669MEDIUMCVSS 4.3EG 4.32024-11-09
The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.4 via the [ctb] shortcode due to insufficient restrictions on wh…
- CVE-2024-10670MEDIUMCVSS 4.3EG 4.32024-11-28
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to insufficient restrictions on which posts can be inclu…
- CVE-2024-10671MEDIUMCVSS 4.3EG 4.32024-11-21
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block] shortcode due to insufficient restrictions on…
- CVE-2024-10688MEDIUMCVSS 4.3EG 4.32024-11-09
The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 via the 'attesa-template' shortcode due to insufficient restrictions on which posts can be included. This makes it poss…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →