CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,017)
An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential documents by manipulating POST paramet...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_de...
Nov 4, 2025An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'web' ...
Nov 4, 2025This vulnerability allows unauthenticated attackers to bypass payment verification in WooCommerce stores using the Crypto Payment Gateway with Payeer ...
Nov 4, 2025This CVE describes a missing authorization vulnerability in BuddyPress that allows unauthorized users to perform actions they shouldn't have access to...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the DELUCKS SEO WordPress plugin that allows attackers to access functionality not properl...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the Tablesome Table Premium WordPress plugin that allows attackers to access functionality...
Oct 22, 2025This CVE describes a Missing Authorization vulnerability in the shinetheme Traveler WordPress theme that allows attackers to delete arbitrary content ...
Sep 26, 2025The AL Pack WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to activate premium features by spoofing...
Aug 16, 2025This CVE describes a Missing Authorization vulnerability in the WP Swings Membership For WooCommerce WordPress plugin that allows attackers to access ...
Aug 14, 2025This CVE describes a Missing Authorization vulnerability in the Eventin Pro WordPress plugin (formerly WordPress Event Manager, Event Calendar and Boo...
Aug 14, 2025CVE-2025-31425 is a missing authorization vulnerability in the WP Lead Capturing Pages WordPress plugin that allows attackers to delete arbitrary cont...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to bypass access contro...
Aug 14, 2025The UiCore Elements WordPress plugin has an arbitrary file read vulnerability that allows unauthenticated attackers to read any file on the server. Th...
Aug 12, 2025This CVE describes a missing authorization vulnerability in Drupal's File Download module that allows forceful browsing (unauthorized file access). At...
Jul 21, 2025This CVE describes a missing authorization vulnerability in the uxper Nuss WordPress theme that allows attackers to access functionality not properly ...
Jul 16, 2025The Ultimate WP Mail WordPress plugin versions 1.0.17 to 1.3.6 contain a privilege escalation vulnerability where authenticated users with Contributor...
Jul 16, 2025The Booking X WordPress plugin versions 1.0 to 1.1.2 contain an authorization bypass vulnerability in the export_now() function that lacks proper capa...
Jul 4, 2025The WP Travel Engine plugin for WordPress has an unauthenticated data deletion vulnerability. Attackers can delete arbitrary posts without authenticat...
Jun 13, 2025A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System allows remote attackers to modify system settings without pro...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the MapSVG WordPress plugin that allows attackers to access functionality not properly res...
May 23, 2025CVE-2025-39451 is a missing authorization vulnerability in Crocoblock's JetBlocks For Elementor WordPress plugin that allows attackers to access funct...
May 19, 2025This CVE describes a missing authorization vulnerability in the Crocoblock JetElements For Elementor WordPress plugin. It allows attackers to access f...
May 19, 2025This vulnerability in the WP ERP WordPress plugin allows employees to access terminated employees' data by manipulating parameters. It affects WordPre...
May 15, 2025This vulnerability allows unauthenticated remote attackers to trigger a shutdown button via HTTPS connections, causing denial of service. Any system r...
Apr 24, 2025A missing authorization vulnerability in synocopy allows remote attackers to read arbitrary files on Synology DiskStation Manager systems. This affect...
Apr 23, 2025This CVE describes a Missing Authorization vulnerability in the JetMenu WordPress plugin that allows attackers to access functionality not properly re...
Apr 15, 2025This CVE describes a broken access control vulnerability in the Unlimited Timeline WordPress plugin that allows unauthorized users to access functiona...
Apr 15, 2025This vulnerability in Oracle E-Business Suite's CRM User Management Framework allows unauthenticated attackers to remotely access sensitive data via H...
Apr 15, 2025A missing authorization vulnerability in the Barcode Generator for WooCommerce WordPress plugin allows attackers to delete arbitrary content without p...
Apr 15, 2025This CVE describes a missing authorization vulnerability in the JetTricks WordPress plugin that allows attackers to access functionality not properly ...
Apr 15, 2025This CVE describes a missing authorization vulnerability in the JetBlog WordPress plugin that allows attackers to access functionality not properly re...
Apr 15, 2025A missing authorization vulnerability in Apptivo Business Site CRM WordPress plugin allows attackers to delete arbitrary content without proper authen...
Apr 3, 2025This CVE describes a missing authorization vulnerability in JoomSky JS Help Desk WordPress plugin that allows attackers to bypass access controls and ...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Greek Multi Tool plugin that allows attackers to bypass access controls. It ...
Apr 1, 2025This vulnerability allows attackers to bypass authorization controls in the Ads by WPQuads WordPress plugin, potentially accessing administrative func...
Mar 31, 2025This vulnerability in lunary-ai/lunary allows any user to export the entire database to Google BigQuery without proper authentication or authorization...
Mar 20, 2025This vulnerability in IROAD V9 dashcams allows unauthorized users to modify device settings, disable critical functions, and turn off battery protecti...
Mar 18, 2025The Trash Duplicate and 301 Redirect WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to delete any posts or ...
Feb 19, 2025This CVE describes a missing authorization vulnerability in the Atarim WordPress plugin that allows attackers to delete arbitrary content without prop...
Feb 18, 2025This vulnerability allows unauthenticated attackers to download the entire WordPress database through the Safe Ai Malware Protection plugin. Any WordP...
Jan 30, 2025This CVE describes a missing authorization vulnerability in the My Tickets WordPress plugin that allows attackers to access functionality not properly...
Jan 21, 2025This CVE describes a Missing Authorization vulnerability in the Standard Box Sizes plugin for WooCommerce that allows unauthorized users to perform ac...
Jan 21, 2025CVE-2024-57757 is an authentication bypass vulnerability in JeeWMS that allows attackers to bypass permission checks in the AuthInterceptor component....
Jan 15, 2025This vulnerability allows unauthenticated attackers to manipulate gift card balances in WooCommerce stores using the Ultimate Gift Cards plugin. Attac...
Jan 8, 2025This CVE describes a missing authorization vulnerability in the Lenderd 1003 Mortgage Application WordPress plugin that allows attackers to access fun...
Jan 7, 2025A missing authorization vulnerability in the EazyDocs WordPress plugin allows attackers to bypass access controls and potentially modify or access res...
Jan 2, 2025This vulnerability allows attackers to bypass authorization controls in the Ultimate Addons for Contact Form 7 WordPress plugin, potentially accessing...
Jan 2, 2025This CVE describes a missing authorization vulnerability in the WP Travel WordPress plugin that allows attackers to exploit incorrectly configured acc...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the Spreadr Woocommerce WordPress plugin that allows attackers to access functionality not...
Dec 18, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,017 CVEs classified as CWE-862, with 220 rated critical and 831 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free