CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,032)
This CVE describes a missing authorization vulnerability in the WordPress Admin Management Xtended plugin that allows attackers to bypass access contr...
Oct 27, 2025This vulnerability in the Find And Replace content WordPress plugin allows unauthenticated attackers to inject malicious scripts into website pages an...
Oct 15, 2025CVE-2025-4477 is a privilege escalation vulnerability in TeamT5's ThreatSonar Anti-Ransomware software. Remote attackers with intermediate privileges ...
May 19, 2025This CVE describes a Missing Authorization vulnerability in the Revenueflex Auto Ad Inserter WordPress plugin that allows unauthorized users to change...
Feb 24, 2025This vulnerability allows unauthenticated attackers to modify Google Sheets integration credentials in Quiz Maker WordPress plugins, potentially leadi...
Jan 26, 2025The ShopWP WordPress plugin has an authorization bypass vulnerability in REST API endpoints that allows unauthenticated attackers to modify plugin set...
Oct 16, 2024The Frontend File Manager WordPress plugin up to version 18.2 allows unauthenticated attackers to send emails with custom HTML content using the site'...
Jun 7, 2023ZoneMinder versions before 1.36.33 and 1.37.33 have an unauthenticated remote code execution vulnerability. Attackers can execute arbitrary commands o...
Feb 25, 2023This vulnerability allows staff-level users in Vehicle Service Management System 1.0 to access admin resources and perform CRUD operations they should...
Jan 6, 2022This vulnerability allows remote attackers to execute arbitrary code on S-CMS PHP v3.0 systems by modifying PHP files through the /1.com.php endpoint....
Jul 30, 2021CVE-2021-33676 is a missing authority check vulnerability in SAP CRM that allows authenticated attackers with high privileges to bypass authorization ...
Jul 14, 2021A local privilege escalation vulnerability in udisks allows unprivileged users to trigger the root-owned daemon to overwrite LUKS encryption headers. ...
Feb 25, 2026This CVE describes a missing authorization vulnerability in the WooCommerce Bulk Product Editor plugin that allows attackers to exploit incorrectly co...
Feb 20, 2026This CVE describes a Missing Authorization vulnerability in CMSMasters Content Composer WordPress plugin that allows attackers to bypass access contro...
Feb 19, 2026This CVE describes an authorization bypass vulnerability in Discourse discussion platform where subscription endpoints lack proper ownership verificat...
Jan 28, 2026This vulnerability allows authenticated GitLab users to access and use AI model settings from namespaces they shouldn't have access to by manipulating...
Jan 9, 2026This CVE describes a missing authorization vulnerability in the Plugin Optimizer WordPress plugin that allows attackers to bypass access controls. Att...
Dec 29, 2025This CVE describes a Missing Authorization vulnerability in the bPlugins Parallax Section WordPress block plugin that allows attackers to access funct...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WPXPO PostX (ultimate-post) WordPress plugin that allows attackers to bypass access co...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the WordPress Info Cards plugin that allows attackers to access functionality not properly...
Nov 6, 2025This CVE describes a Missing Authorization vulnerability in the UkrSolution Barcode Scanner with Inventory & Order Manager WordPress plugin. It allows...
Aug 31, 2025This CVE describes a missing authorization vulnerability in the bPlugins Tiktok Feed WordPress plugin that allows attackers to access functionality no...
Aug 28, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Project Cost Calculator plugin that allows attackers to bypass access contro...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the PW WooCommerce On Sale! WordPress plugin that allows attackers to bypass access contro...
Jul 16, 2025This CVE describes a Missing Authorization vulnerability in the Icegram Collect WordPress plugin that allows attackers to bypass access controls. It a...
Jun 9, 2025This CVE describes a missing authorization vulnerability in the Stock Locations for WooCommerce WordPress plugin. It allows attackers to bypass access...
Jun 9, 2025The Hive Support WordPress plugin has missing capability checks that allow authenticated users with Subscriber-level access or higher to read and over...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to delete arbitrary content without p...
Apr 17, 2025This CVE describes a Missing Authorization vulnerability in the Doppler Forms WordPress plugin that allows attackers to bypass access controls. It aff...
Apr 17, 2025This vulnerability allows low-privilege users to modify checklists in lunary-ai/lunary version 1.4.28 by exploiting missing access controls on the /ch...
Mar 20, 2025CVE-2024-2292 is an access control vulnerability that allows unauthorized users to view and modify other users' information due to missing authorizati...
Mar 20, 2025This CVE describes a Missing Authorization vulnerability in the Squirrly SEO WordPress plugin that allows unauthorized users to perform actions that s...
Mar 3, 2025This vulnerability allows unauthorized users to modify WordPress menu settings due to missing access control checks in the Bulk Menu Edit plugin. Word...
Feb 14, 2025This vulnerability allows authenticated low-privileged attackers to remove users from groups in Q-Free MaxTime systems via crafted HTTP requests. It a...
Feb 12, 2025This vulnerability allows authenticated low-privileged attackers to remove privileges from user groups in Q-Free MaxTime traffic management systems. A...
Feb 12, 2025This CVE describes a Missing Authorization vulnerability in the Cab fare calculator WordPress plugin that allows attackers to perform Stored Cross-Sit...
Jan 27, 2025This CVE describes a missing authorization vulnerability in Crocoblock's JetEngine WordPress plugin that allows attackers to bypass access controls. A...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the WordPress My Shortcodes plugin that allows attackers to exploit incorrectly configured...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the Seerox Easy Blocks Pro WordPress plugin that allows attackers to access functionality ...
Dec 13, 2024The RapidLoad WordPress plugin has missing capability checks on multiple AJAX functions, allowing authenticated users with Subscriber-level access or ...
Dec 11, 2024This CVE describes a missing authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls a...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Meta Box WordPress plugin that allows attackers to bypass access controls and perform ...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the EazyDocs WordPress plugin that allows attackers to bypass access controls and perform ...
Nov 1, 2024This CVE describes a path deletion vulnerability in macOS that allows applications to bypass Privacy preferences. It affects macOS Ventura and Sonoma ...
Oct 28, 2024The Paytium WordPress plugin versions up to 4.3.7 lack proper capability checks, allowing authenticated users with subscriber-level permissions to cre...
Oct 16, 2024The Paytium WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level permissions to create Mollie pay...
Oct 16, 2024The Tutor LMS Pro WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or higher...
Aug 30, 2024The Brizy Page Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with contributor-level access or hig...
Jul 16, 2024This CVE describes a Missing Authorization vulnerability in Slider Revolution WordPress plugin that allows unauthenticated attackers to perform unauth...
Jun 19, 2024This CVE describes a missing authorization vulnerability in the WordPress Convert Pro plugin that allows unauthorized users to access administrative f...
Jun 19, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,032 CVEs classified as CWE-862, with 224 rated critical and 842 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free