CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (2,998)
A permission control vulnerability in Huawei's App Multiplier module allows unauthorized access to sensitive functionality. This affects Huawei device...
Aug 8, 2024The TOTOLINK EX200 V4.0.3c.7646_B20201211 wireless range extender lacks any authentication mechanism by default, allowing unauthenticated attackers to...
Apr 8, 2024CVE-2025-65036 is a critical vulnerability in XWiki Remote Macros that allows unauthenticated attackers to execute arbitrary code via Velocity templat...
Dec 5, 2025This CVE describes a Missing Authorization vulnerability in the FS Poster WordPress plugin that allows unauthorized users to perform actions intended ...
Apr 16, 2025This CVE describes a Missing Authorization vulnerability in the PrivateContent WordPress plugin that allows attackers to bypass access controls. Attac...
Mar 15, 2025This CVE describes a Missing Authorization vulnerability in the JupiterX Core WordPress plugin that allows attackers to exploit incorrectly configured...
Dec 13, 2024This CVE describes a WordPress plugin vulnerability where attackers can bypass authorization controls to access administrative functions and inject ma...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Essential Grid WordPress plugin by ThemePunch OHG. It allows authenticated users to pe...
Jun 19, 2024CVE-2023-25799 is a missing authorization vulnerability in the Tutor LMS WordPress plugin that allows unauthorized users to access student data and pe...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the AA-Team WZone WordPress plugin, allowing unauthorized users to perform actions intende...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows attackers to perform unau...
Jun 9, 2024The CMP Coming Soon & Maintenance plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to read posts, ...
Jun 7, 2023This CVE describes a missing authorization vulnerability in the WordPress User Registration plugin that allows attackers to bypass access controls. It...
Jan 22, 2026The iPaymu Payment Gateway for WooCommerce WordPress plugin has a missing authentication vulnerability that allows unauthenticated attackers to mark o...
Jan 7, 2026An unauthenticated Broken Function Level Authorization vulnerability in Newgen OmniDocs v11.0 allows attackers to bypass authentication and access pri...
Dec 15, 2025This vulnerability allows attackers to bypass authorization controls in the WP Messiah Ai Image Alt Text Generator WordPress plugin, enabling unauthor...
Nov 6, 2025This CVE describes a Missing Authorization vulnerability in WPGuppy Lite WordPress plugin that allows attackers to access functionality not properly c...
Oct 22, 2025The Cloud SAML SSO WordPress plugin has a missing capability check that allows unauthenticated attackers to modify organization settings via POST requ...
Sep 6, 2025This vulnerability allows attackers to bypass authorization controls in the Abandoned Contact Form 7 WordPress plugin, potentially accessing sensitive...
Jun 27, 2025This CVE describes a Missing Authorization vulnerability in the Chimpstudio JobHunt Job Alerts WordPress plugin that allows attackers to delete arbitr...
May 23, 2025This vulnerability allows attackers to delete arbitrary WordPress options without proper authorization in the Grand Restaurant WordPress theme. Any Wo...
May 19, 2025This CVE describes a Missing Authorization vulnerability in the Add Product Frontend for WooCommerce WordPress plugin that allows attackers to delete ...
Apr 17, 2025This CVE describes a Missing Authorization vulnerability in Drupal AI that allows attackers to access restricted functionality through forceful browsi...
Mar 31, 2025This CVE describes a Missing Authorization vulnerability in the Shinetheme Traveler WordPress theme that allows unauthorized users to perform actions ...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the BookPress WordPress plugin that allows attackers to bypass access controls. Attackers ...
Feb 7, 2025This vulnerability allows unauthorized attackers to elevate privileges in Microsoft Account systems over a network. Attackers can gain higher-level ac...
Jan 29, 2025This CVE describes a missing authorization vulnerability in the Realty Workstation WordPress plugin that allows attackers to access functionality not ...
Jan 21, 2025This vulnerability allows attackers to bypass authorization controls in MultiVendorX WC Marketplace WordPress plugin, potentially accessing or modifyi...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Flexible Woocommerce Checkout Field Editor WordPress plugin that allows attackers to b...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Stripe Payments WordPress plugin that allows attackers to bypass access controls. It a...
Dec 9, 2024This vulnerability allows attackers with access to a victim's Personal Access Token (PAT) to escalate privileges in GitLab instances. It affects all G...
Nov 26, 2024This vulnerability allows unauthenticated attackers to access functionality that should be restricted by proper authorization controls in the Woffice ...
Nov 1, 2024CVE-2024-37106 is a missing authorization vulnerability in the WishList Member X WordPress plugin that allows unauthenticated attackers to change plug...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the MasterStudy LMS WordPress plugin that allows attackers to bypass access controls and p...
Nov 1, 2024This CVE describes an authorization bypass vulnerability in Mastodon where attackers can craft specific activities to extend the audience of posts the...
Jul 5, 2024This CVE describes a Missing Authorization vulnerability in the Betheme WordPress theme that allows unauthorized users to perform actions intended onl...
Jun 19, 2024This vulnerability allows unauthenticated attackers to bypass authorization controls in the Paid Memberships Pro CCBill Gateway WordPress plugin. Atta...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the EventPrime WordPress plugin that allows attackers to manipulate booking prices without...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Olive One Click Demo Import WordPress plugin. It allows unauthenticated attackers to i...
Mar 20, 2024This vulnerability in Spring Security allows broken access control when applications directly use AuthenticatedVoter#vote with a null Authentication p...
Mar 18, 2024This vulnerability allows unauthenticated attackers to modify content on WordPress sites using the SeedProd Website Builder plugin. Attackers can chan...
Feb 5, 2024CVE-2023-1261 is a missing MAC layer security vulnerability in Silicon Labs Wi-SUN SDK that allows malicious nodes to route unauthorized messages thro...
Mar 21, 2023This vulnerability in the WordPress Restrict Content plugin allows unauthenticated attackers to register with any membership level, including inactive...
Mar 5, 2026This CVE describes a Missing Authorization vulnerability in the Tablesome WordPress plugin that allows attackers to bypass access controls and perform...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the WP Recipe Maker WordPress plugin that allows attackers to bypass access controls. It a...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the WordPress User Registration plugin that allows attackers to exploit incorrectly config...
Jan 22, 2026Fleet device management software versions before 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 have broken access control that allows any authenticated u...
Jan 21, 2026This vulnerability allows attackers to bypass authorization controls in ManageEngine's privileged access management products when initiating remote se...
Jan 13, 2026This vulnerability allows backend users with access to the recycler module to delete arbitrary data from any database table defined in TYPO3's TCA, re...
Jan 13, 2026This CVE describes a Missing Authorization Check vulnerability in SAP ABAP systems that allows authenticated attackers to misuse RFC functions to exec...
Jan 13, 2026About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 2,998 CVEs classified as CWE-862, with 213 rated critical and 819 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free