CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,031
Total CVEs
224
Critical
841
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,031)

CVE-2024-11916
7.4

The WP Extended WordPress plugin has a missing capability check vulnerability that allows authenticated attackers with subscriber-level access or high...

Jan 8, 2025
CVE-2024-2544
7.4

The Popup Builder WordPress plugin has a missing capability check on all AJAX actions, allowing authenticated attackers with subscriber-level access o...

Jun 15, 2024
CVE-2023-1299
7.4

This vulnerability in HashiCorp Nomad allows job submitters to escalate privileges to management-level access using workload identity and task API fea...

Mar 14, 2023
CVE-2022-21953
7.4

This CVE-2022-21953 is a missing authorization vulnerability in SUSE Rancher that allows authenticated users to create unauthorized shell pods and gai...

Feb 7, 2023
CVE-2026-0832
7.3

The New User Approve WordPress plugin has missing capability checks on REST API endpoints, allowing unauthenticated attackers to approve/deny user reg...

Jan 28, 2026
CVE-2025-69191
7.3

This CVE describes a Missing Authorization vulnerability in the WordPress ListingHub plugin that allows attackers to bypass access controls. It affect...

Jan 22, 2026
CVE-2025-69192
7.3

This CVE describes a missing authorization vulnerability in the Real Estate Pro WordPress plugin that allows attackers to bypass access controls. Atta...

Jan 22, 2026
CVE-2025-69193
7.3

This CVE describes a missing authorization vulnerability in the WP Membership WordPress plugin that allows attackers to bypass access controls. Attack...

Jan 22, 2026
CVE-2025-69187
7.3

This CVE describes a Missing Authorization vulnerability in the WordPress Final User plugin that allows attackers to bypass access controls. Attackers...

Jan 22, 2026
CVE-2025-69188
7.3

This CVE describes a missing authorization vulnerability in the WordPress fitness-trainer plugin that allows attackers to bypass access controls. Atta...

Jan 22, 2026
CVE-2025-69190
7.3

This CVE describes a missing authorization vulnerability in the Listihub WordPress theme that allows attackers to bypass access controls. Attackers ca...

Jan 22, 2026
CVE-2025-69185
7.3

This CVE describes a missing authorization vulnerability in the Hotel Listing WordPress plugin that allows attackers to bypass access controls. Attack...

Jan 22, 2026
CVE-2025-69186
7.3

This CVE describes a Missing Authorization vulnerability in the Hospital Doctor Directory WordPress plugin that allows attackers to bypass access cont...

Jan 22, 2026
CVE-2025-69184
7.3

This CVE describes a missing authorization vulnerability in the WordPress Institutions Directory plugin that allows attackers to bypass access control...

Jan 22, 2026
CVE-2025-69181
7.3

This CVE describes a missing authorization vulnerability in the Lawyer Directory WordPress plugin that allows attackers to bypass access controls. It ...

Jan 22, 2026
CVE-2025-13063
7.3

DinukaNavaratna Dee Store 1.0 has a missing authorization vulnerability (CWE-862) that allows remote attackers to access multiple endpoints without pr...

Nov 12, 2025
CVE-2025-12925
7.3

This CVE describes an authorization bypass vulnerability in rymcu forest's UserDicController API endpoints. Attackers can remotely manipulate user dic...

Nov 10, 2025
CVE-2025-49950
7.3

This CVE describes a missing authorization vulnerability in the Billingo Official Integration WordPress plugin that allows authenticated attackers to ...

Oct 22, 2025
CVE-2025-49925
7.3

This CVE describes a Missing Authorization vulnerability in the WPLMS WordPress plugin by VibeThemes, allowing attackers to access functionality not p...

Oct 22, 2025
CVE-2025-52801
7.3

This CVE describes a missing authorization vulnerability in the VonStroheim TheBooking WordPress plugin that allows attackers to access functionality ...

Aug 14, 2025
CVE-2025-8435
7.3

CVE-2025-8435 is a critical missing authorization vulnerability in code-projects Online Movie Streaming 1.0 that allows attackers to bypass authentica...

Aug 1, 2025
CVE-2025-8434
7.3

This critical vulnerability in code-projects Online Movie Streaming 1.0 allows unauthorized access to admin.php functionality by manipulating the ID p...

Aug 1, 2025
CVE-2025-41231
7.3

VMware Cloud Foundation contains a missing authorization vulnerability that allows authenticated users to perform unauthorized actions and access limi...

May 20, 2025
CVE-2025-4179
7.3

The Flynax Bridge WordPress plugin has a privilege escalation vulnerability that allows unauthenticated attackers to register new user accounts with a...

May 2, 2025
CVE-2025-3963
7.3

CVE-2025-3963 is a critical missing authorization vulnerability in withstars Books-Management-System 1.0 that allows unauthenticated attackers to acce...

Apr 27, 2025
CVE-2025-3960
7.3

CVE-2025-3960 is a critical missing authorization vulnerability in withstars Books-Management-System 1.0 that allows unauthenticated attackers to acce...

Apr 27, 2025
CVE-2025-2262
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Logo Slider plugin. Attackers could inject m...

Mar 18, 2025
CVE-2023-45104
7.3

This CVE describes a missing authorization vulnerability in the WordPress BetterLinks plugin that allows attackers to bypass access controls and perfo...

Jan 2, 2025
CVE-2023-36510
7.3

This CVE describes a missing authorization vulnerability in the ReDi Restaurant Reservation WordPress plugin that allows attackers to bypass access co...

Dec 13, 2024
CVE-2023-32507
7.3

This CVE describes a Missing Authorization vulnerability in the Woo Custom Emails WordPress plugin that allows attackers to exploit incorrectly config...

Dec 13, 2024
CVE-2024-39650
7.3

This CVE describes a Missing Authorization vulnerability in the WPWeb Elite WooCommerce PDF Vouchers plugin for WordPress. It allows unauthenticated a...

Nov 1, 2024
CVE-2024-39664
7.3

This CVE describes a Missing Authorization vulnerability in the YMC Filter & Grids WordPress plugin that allows attackers to access functionality not ...

Nov 1, 2024
CVE-2024-10078
7.3

The WP Easy Post Types WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or h...

Oct 18, 2024
CVE-2020-36840
7.3

The Timetable and Event Schedule WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to execute AJAX func...

Oct 16, 2024
CVE-2023-36515
7.3

CVE-2023-36515 is a missing authorization vulnerability in the LearnPress WordPress plugin that allows unauthenticated attackers to perform actions th...

Jun 19, 2024
CVE-2024-4222
7.3

The Tutor LMS Pro WordPress plugin up to version 2.7.0 lacks proper capability checks on multiple functions, allowing unauthenticated attackers to add...

May 16, 2024
CVE-2024-0683
7.3

The Bulgarisation for WooCommerce WordPress plugin has missing capability checks that allow unauthorized users to generate and delete labels. This aff...

Mar 13, 2024
CVE-2024-0702
7.3

The Oliver POS WordPress plugin has missing capability checks on AJAX functions, allowing authenticated attackers with subscriber-level access or high...

Feb 29, 2024
CVE-2023-6751
7.3

The Hostinger WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to enable or disable maintenance mode ...

Jan 11, 2024
CVE-2023-6007
7.3

The UserPro WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to add, modify, or delete user metadat...

Nov 22, 2023
CVE-2023-36815
7.3

CVE-2023-36815 is a privilege escalation vulnerability in Sealos Cloud Operating System's billing system that allows authenticated users to manipulate...

Jul 3, 2023
CVE-2020-36716
7.3

The WP Activity Log plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to run the plugin's setup wiz...

Jun 7, 2023
CVE-2022-20126
7.3

This vulnerability allows a malicious app on an Android device to enable Bluetooth discovery mode without user permission, potentially exposing the de...

Jun 15, 2022
CVE-2025-15041
7.2

This vulnerability in the BackWPup WordPress plugin allows authenticated attackers with subscriber-level access or higher to modify WordPress site opt...

Feb 19, 2026
CVE-2025-12975
7.2

This vulnerability allows authenticated attackers with Shop Manager or higher WordPress roles to install arbitrary plugins via the CTX Feed plugin. Th...

Feb 19, 2026
CVE-2026-0845
7.2

This vulnerability allows authenticated attackers with Shop Manager or higher privileges in WordPress to modify arbitrary site options due to missing ...

Feb 10, 2026
CVE-2025-14657
7.2

This vulnerability in the Eventin WordPress plugin allows unauthenticated attackers to modify plugin settings and inject malicious scripts. Attackers ...

Jan 9, 2026
CVE-2025-64255
7.2

This CVE describes a missing authorization vulnerability in the Bowo Admin and Site Enhancements (ASE) WordPress plugin that allows attackers to bypas...

Dec 9, 2025
CVE-2025-11620
7.2

The Multiple Roles per User WordPress plugin has an authorization vulnerability that allows authenticated users with 'edit_users' capability to modify...

Nov 18, 2025
CVE-2025-62965
7.2

This CVE describes a missing authorization vulnerability in the WordPress Admin Management Xtended plugin that allows attackers to bypass access contr...

Oct 27, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,031 CVEs classified as CWE-862, with 224 rated critical and 841 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free