CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 8 of 43
- CVE-2022-40186CRITICALCVSS 9.1EG 9.12022-09-22
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrit…
- CVE-2022-40205MEDIUMCVSS 5.4EG 5.42022-11-08
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
- CVE-2022-40206MEDIUMCVSS 6.3EG 6.32022-11-08
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
- CVE-2022-40319HIGHCVSS 7.5EG 7.52023-01-17
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
- CVE-2022-4097MEDIUMCVSS 5.3EG 5.32022-12-12
The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).
- CVE-2022-41479HIGHCVSS 7.5EG 7.52022-10-18
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) v…
- CVE-2022-42067MEDIUMCVSS 4.3EG 4.32022-10-14
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
- CVE-2022-42129MEDIUMCVSS 4.3EG 4.32022-11-15
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form …
- CVE-2022-42175HIGHCVSS 8.8EG 8.82023-07-05
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.
- CVE-2022-4239MEDIUMCVSS 6.5EG 6.52022-12-26
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to…
- CVE-2022-43326HIGHCVSS 7.5EG 7.52022-11-29
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.
- CVE-2022-4340MEDIUMCVSS 5.3EG 5.32023-01-02
The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time an…
- CVE-2022-43450MEDIUMCVSS 4.3EG 4.32023-12-19
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
- CVE-2022-43492HIGHCVSS 4.3EG 8.82022-11-18
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
- CVE-2022-44005MEDIUMCVSS 5.3EG 5.32022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is p…
- CVE-2022-4417MEDIUMCVSS 5.3EG 5.32023-01-02
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place…
- CVE-2022-4505HIGHCVSS 8.8EG 8.82022-12-15
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
- CVE-2022-45175MEDIUMCVSS 6.5EG 6.52023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in th…
- CVE-2022-4550HIGHCVSS 7.5EG 7.52023-02-27
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
- CVE-2022-45927HIGHCVSS 8.8EG 8.82023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects …
- CVE-2022-46179CRITICALCVSS 9.2EG 9.22022-12-28
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip au…
- CVE-2022-4686CRITICALCVSS 9.8EG 9.82022-12-23
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-4794HIGHCVSS 7.5EG 7.52023-01-30
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
- CVE-2022-4798MEDIUMCVSS 5.3EG 5.32022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4799MEDIUMCVSS 6.5EG 6.52022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4802MEDIUMCVSS 5.4EG 5.42022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4803HIGHCVSS 8.8EG 8.82022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4806MEDIUMCVSS 5.3EG 5.32022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4811HIGHCVSS 8.3EG 8.32022-12-28
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
- CVE-2022-4812MEDIUMCVSS 6.5EG 6.52022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-48313MEDIUMCVSS 6.5EG 6.52023-04-16
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2022-48505MEDIUMCVSS 5.5EG 5.52023-06-28
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system
- CVE-2023-0453MEDIUMCVSS 4.3EG 4.32023-02-21
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users t…
- CVE-2023-0550HIGHCVSS 8.1EG 8.12023-01-27
The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that …
- CVE-2023-0558CRITICALCVSS 8.2EG 9.82023-01-27
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers …
- CVE-2023-0688MEDIUMCVSS 6.5EG 6.52023-06-09
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabiliti…
- CVE-2023-0689MEDIUMCVSS 4.3EG 4.32023-08-31
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabili…
- CVE-2023-0691MEDIUMCVSS 4.3EG 4.32023-06-09
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilit…
- CVE-2023-0692MEDIUMCVSS 4.3EG 4.32023-06-09
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capa…
- CVE-2023-0693MEDIUMCVSS 6.5EG 6.52023-06-09
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capa…
- CVE-2023-0694MEDIUMCVSS 6.5EG 6.52023-06-09
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or abo…
- CVE-2023-0749MEDIUMCVSS 6.5EG 6.52023-03-13
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as dr…
- CVE-2023-0772MEDIUMCVSS 6.5EG 6.52023-03-13
The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbi…
- CVE-2023-0816MEDIUMCVSS 6.5EG 6.52023-03-27
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
- CVE-2023-0865HIGHCVSS 8.8EG 8.82023-03-20
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allo…
- CVE-2023-0882HIGHCVSS 8.8EG 8.82023-02-17
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16.
- CVE-2023-0967MEDIUMCVSS 6.5EG 6.52023-04-05
Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vuln…
- CVE-2023-0985HIGHCVSS 8.8EG 8.82023-06-06
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any u…
- CVE-2023-1125MEDIUMCVSS 6.5EG 6.52023-05-02
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
- CVE-2023-1129MEDIUMCVSS 6.5EG 6.52023-04-24
The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →