CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,010)
CVE-2026-0490 is an authentication bypass vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to send crafted netwo...
Feb 10, 2026This vulnerability in Hollo microblogging software exposes private direct messages and followers-only posts through the ActivityPub outbox endpoint wi...
Feb 9, 2026The SEO Flow by LupsOnline WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to create, modify, and del...
Feb 4, 2026This vulnerability in the Frontend File Manager WordPress plugin allows unauthenticated attackers to share any uploaded file via email by exploiting a...
Jan 28, 2026This CVE describes a missing authorization vulnerability in the WPXPO PostX ultimate-post WordPress plugin that allows attackers to bypass access cont...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Scalenut WordPress plugin that allows attackers to bypass access controls. It affects ...
Jan 22, 2026The Reviewify WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or higher to create ar...
Jan 7, 2026This vulnerability in the Latest Registered Users WordPress plugin allows unauthenticated attackers to export complete user data (excluding passwords)...
Jan 7, 2026The User Activity Log WordPress plugin up to version 2.2 contains an unauthenticated vulnerability that allows attackers to modify critical WordPress ...
Jan 7, 2026This CVE describes a missing authorization vulnerability in CubeWP WordPress plugin that allows attackers to access functionality not properly restric...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the claspo Popup Builder WordPress plugin that allows attackers to bypass access controls....
Dec 24, 2025CVE-2024-24844 is a missing authorization vulnerability in PowerPack Pro for Elementor WordPress plugin that allows unauthenticated attackers to reset...
Dec 23, 2025This vulnerability allows unauthenticated attackers to access sensitive user metadata including password hashes via a REST API endpoint in the PostX W...
Dec 21, 2025This CVE describes a Missing Authorization vulnerability in the Ays Pro Easy Form WordPress plugin that allows attackers to bypass access controls. It...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the LearnPress WordPress plugin that allows attackers to bypass access controls and perfor...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the wpForo Forum WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 18, 2025This CVE describes a missing authorization vulnerability in PropertyHive WordPress plugin that allows attackers to bypass access controls. It affects ...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. It affects...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to bypass access controls. I...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the GetResponse Email Marketing WordPress plugin that allows attackers to exploit incorrec...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the FantasticPlugins WooCommerce Recover Abandoned Cart plugin that allows attackers to de...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the Masterstudy WordPress theme that allows attackers to access functionality not properly...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the MasterStudy LMS Pro WordPress plugin that allows attackers to access functionality not...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WP Voting Contest WordPress plugin that allows attackers to exploit incorrectly config...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the YayPricing WordPress plugin that allows attackers to access functionality not properly...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to access functionality...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Javo Core WordPress plugin that allows attackers to delete arbitrary content without p...
Dec 18, 2025This CVE describes a missing authorization vulnerability in Synology BeeDrive desktop software that allows remote attackers to delete arbitrary files ...
Dec 4, 2025Ruoyi v4.8.0 has an incorrect access control vulnerability where the authRole method in SysUserController.java lacks a checkUserDataScope permission c...
Nov 26, 2025Ruoyi v4.8.0 has an incorrect access control vulnerability in the resetPwd method that allows unauthorized password resets. Attackers can reset passwo...
Nov 26, 2025This vulnerability allows unauthenticated attackers to forge PayPal payment notifications in the CP Contact Form with PayPal WordPress plugin, marking...
Nov 22, 2025The Live Sales Notification for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to access...
Nov 18, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability that allows attackers to craft documents that automatically load ...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where specially crafted Calc spreadsheets containing DDE links ca...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 contain a missing authorization vulnerability where documents with floating frames linked to external files ...
Nov 12, 2025The Bookit WordPress plugin has a missing capability check on its Stripe return endpoint, allowing unauthenticated attackers to connect their own Stri...
Nov 12, 2025This CVE describes a Missing Authorization vulnerability in the Miraculous WordPress theme that allows attackers to delete arbitrary content without p...
Nov 6, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating POST param...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating the 'web' parameter in ...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating the 'web' parameter in ...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating POST parameters. Attack...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_so...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential reports by manipulating the 'id_denunc...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential documents by manipulating POST paramet...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_de...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'web' ...
Nov 4, 2025This vulnerability allows unauthenticated attackers to bypass payment verification in WooCommerce stores using the Crypto Payment Gateway with Payeer ...
Nov 4, 2025This CVE describes a missing authorization vulnerability in BuddyPress that allows unauthorized users to perform actions they shouldn't have access to...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the DELUCKS SEO WordPress plugin that allows attackers to access functionality not properl...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the Tablesome Table Premium WordPress plugin that allows attackers to access functionality...
Oct 22, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,010 CVEs classified as CWE-862, with 217 rated critical and 827 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free