CVE-2026-39701
Missing Authorization vulnerability in Andrew ShopWP wpshopify allows Exploiting Incorrectly Configured Access Control Security Levels.This
CVSS
5.3
Medio
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 8 abr 2026 · Última mod.: 24 jul 2026 · CWE-862
0.2%EPSS · 30 días0.2%
2026-07-292026-08-26
Missing Authorization vulnerability in Andrew ShopWP wpshopify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopWP: from n/a through <= 5.2.4.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-782666.5 MED14.1%
——4Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.2dCVE-2026-273646.5 MED13.6%
——4Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.2dCVE-2026-715096.5 MED14.9%
——4Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity fields. Attackers can manipulate workflow state fields through the REST API to advance expense reports to approved or closed status without possessing the dedicated approval right, while also creating forensic inconsistencies in audit records due to missing approval timestamps.3dCVE-2026-715086.5 MED12.4%
——4Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.3dCVE-2026-715048.1 ALT17.1%
——5Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.3dCVE-2026-719339.1 CRÍ30.7%
——9Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.3d