CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,032
Total CVEs
224
Critical
842
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,032)

CVE-2025-62965
7.2

This CVE describes a missing authorization vulnerability in the WordPress Admin Management Xtended plugin that allows attackers to bypass access contr...

Oct 27, 2025
CVE-2025-10313
7.2

This vulnerability in the Find And Replace content WordPress plugin allows unauthenticated attackers to inject malicious scripts into website pages an...

Oct 15, 2025
CVE-2025-4477
7.2

CVE-2025-4477 is a privilege escalation vulnerability in TeamT5's ThreatSonar Anti-Ransomware software. Remote attackers with intermediate privileges ...

May 19, 2025
CVE-2025-27296
7.2

This CVE describes a Missing Authorization vulnerability in the Revenueflex Auto Ad Inserter WordPress plugin that allows unauthorized users to change...

Feb 24, 2025
CVE-2024-10574
7.2

This vulnerability allows unauthenticated attackers to modify Google Sheets integration credentials in Quiz Maker WordPress plugins, potentially leadi...

Jan 26, 2025
CVE-2019-25214
7.2

The ShopWP WordPress plugin has an authorization bypass vulnerability in REST API endpoints that allows unauthenticated attackers to modify plugin set...

Oct 16, 2024
CVE-2021-4350
7.2

The Frontend File Manager WordPress plugin up to version 18.2 allows unauthenticated attackers to send emails with custom HTML content using the site'...

Jun 7, 2023
CVE-2023-26035
7.2

ZoneMinder versions before 1.36.33 and 1.37.33 have an unauthenticated remote code execution vulnerability. Attackers can execute arbitrary commands o...

Feb 25, 2023
CVE-2021-46075
7.2

This vulnerability allows staff-level users in Vehicle Service Management System 1.0 to access admin resources and perform CRUD operations they should...

Jan 6, 2022
CVE-2020-20698
7.2

This vulnerability allows remote attackers to execute arbitrary code on S-CMS PHP v3.0 systems by modifying PHP files through the /1.com.php endpoint....

Jul 30, 2021
CVE-2021-33676
7.2

CVE-2021-33676 is a missing authority check vulnerability in SAP CRM that allows authenticated attackers with high privileges to bypass authorization ...

Jul 14, 2021
CVE-2026-26103
7.1

A local privilege escalation vulnerability in udisks allows unprivileged users to trigger the root-owned daemon to overwrite LUKS encryption headers. ...

Feb 25, 2026
CVE-2025-69381
7.1

This CVE describes a missing authorization vulnerability in the WooCommerce Bulk Product Editor plugin that allows attackers to exploit incorrectly co...

Feb 20, 2026
CVE-2026-23547
7.1

This CVE describes a Missing Authorization vulnerability in CMSMasters Content Composer WordPress plugin that allows attackers to bypass access contro...

Feb 19, 2026
CVE-2025-68479
7.1

This CVE describes an authorization bypass vulnerability in Discourse discussion platform where subscription endpoints lack proper ownership verificat...

Jan 28, 2026
CVE-2025-13772
7.1

This vulnerability allows authenticated GitLab users to access and use AI model settings from namespaces they shouldn't have access to by manipulating...

Jan 9, 2026
CVE-2025-68861
7.1

This CVE describes a missing authorization vulnerability in the Plugin Optimizer WordPress plugin that allows attackers to bypass access controls. Att...

Dec 29, 2025
CVE-2025-60079
7.1

This CVE describes a Missing Authorization vulnerability in the bPlugins Parallax Section WordPress block plugin that allows attackers to access funct...

Dec 18, 2025
CVE-2025-54751
7.1

This CVE describes a Missing Authorization vulnerability in the WPXPO PostX (ultimate-post) WordPress plugin that allows attackers to bypass access co...

Dec 18, 2025
CVE-2025-54711
7.1

This CVE describes a missing authorization vulnerability in the WordPress Info Cards plugin that allows attackers to access functionality not properly...

Nov 6, 2025
CVE-2024-32589
7.1

This CVE describes a Missing Authorization vulnerability in the UkrSolution Barcode Scanner with Inventory & Order Manager WordPress plugin. It allows...

Aug 31, 2025
CVE-2025-54710
7.1

This CVE describes a missing authorization vulnerability in the bPlugins Tiktok Feed WordPress plugin that allows attackers to access functionality no...

Aug 28, 2025
CVE-2025-52775
7.1

This CVE describes a Missing Authorization vulnerability in the WordPress Project Cost Calculator plugin that allows attackers to bypass access contro...

Aug 14, 2025
CVE-2025-49888
7.1

This CVE describes a missing authorization vulnerability in the PW WooCommerce On Sale! WordPress plugin that allows attackers to bypass access contro...

Jul 16, 2025
CVE-2025-47527
7.1

This CVE describes a Missing Authorization vulnerability in the Icegram Collect WordPress plugin that allows attackers to bypass access controls. It a...

Jun 9, 2025
CVE-2025-47463
7.1

This CVE describes a missing authorization vulnerability in the Stock Locations for WooCommerce WordPress plugin. It allows attackers to bypass access...

Jun 9, 2025
CVE-2025-5018
7.1

The Hive Support WordPress plugin has missing capability checks that allow authenticated users with Subscriber-level access or higher to read and over...

Jun 6, 2025
CVE-2025-39583
7.1

This CVE describes a Missing Authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to delete arbitrary content without p...

Apr 17, 2025
CVE-2025-32620
7.1

This CVE describes a Missing Authorization vulnerability in the Doppler Forms WordPress plugin that allows attackers to bypass access controls. It aff...

Apr 17, 2025
CVE-2024-9096
7.1

This vulnerability allows low-privilege users to modify checklists in lunary-ai/lunary version 1.4.28 by exploiting missing access controls on the /ch...

Mar 20, 2025
CVE-2024-2292
7.1

CVE-2024-2292 is an access control vulnerability that allows unauthorized users to view and modify other users' information due to missing authorizati...

Mar 20, 2025
CVE-2025-24654
7.1

This CVE describes a Missing Authorization vulnerability in the Squirrly SEO WordPress plugin that allows unauthorized users to perform actions that s...

Mar 3, 2025
CVE-2025-24692
7.1

This vulnerability allows unauthorized users to modify WordPress menu settings due to missing access control checks in the Bulk Menu Edit plugin. Word...

Feb 14, 2025
CVE-2025-26372
7.1

This vulnerability allows authenticated low-privileged attackers to remove users from groups in Q-Free MaxTime systems via crafted HTTP requests. It a...

Feb 12, 2025
CVE-2025-26370
7.1

This vulnerability allows authenticated low-privileged attackers to remove privileges from user groups in Q-Free MaxTime traffic management systems. A...

Feb 12, 2025
CVE-2025-23982
7.1

This CVE describes a Missing Authorization vulnerability in the Cab fare calculator WordPress plugin that allows attackers to perform Stored Cross-Sit...

Jan 27, 2025
CVE-2023-48758
7.1

This CVE describes a missing authorization vulnerability in Crocoblock's JetEngine WordPress plugin that allows attackers to bypass access controls. A...

Jan 2, 2025
CVE-2023-46632
7.1

This CVE describes a Missing Authorization vulnerability in the WordPress My Shortcodes plugin that allows attackers to exploit incorrectly configured...

Jan 2, 2025
CVE-2024-54256
7.1

This CVE describes a Missing Authorization vulnerability in the Seerox Easy Blocks Pro WordPress plugin that allows attackers to access functionality ...

Dec 13, 2024
CVE-2024-11840
7.1

The RapidLoad WordPress plugin has missing capability checks on multiple AJAX functions, allowing authenticated users with Subscriber-level access or ...

Dec 11, 2024
CVE-2024-47314
7.1

This CVE describes a missing authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls a...

Nov 1, 2024
CVE-2024-43235
7.1

This CVE describes a Missing Authorization vulnerability in the Meta Box WordPress plugin that allows attackers to bypass access controls and perform ...

Nov 1, 2024
CVE-2024-38721
7.1

This CVE describes a Missing Authorization vulnerability in the EazyDocs WordPress plugin that allows attackers to bypass access controls and perform ...

Nov 1, 2024
CVE-2024-44156
7.1

This CVE describes a path deletion vulnerability in macOS that allows applications to bypass Privacy preferences. It affects macOS Ventura and Sonoma ...

Oct 28, 2024
CVE-2023-7294
7.1

The Paytium WordPress plugin versions up to 4.3.7 lack proper capability checks, allowing authenticated users with subscriber-level permissions to cre...

Oct 16, 2024
CVE-2023-7291
7.1

The Paytium WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level permissions to create Mollie pay...

Oct 16, 2024
CVE-2024-5784
7.1

The Tutor LMS Pro WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or higher...

Aug 30, 2024
CVE-2024-1937
7.1

The Brizy Page Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with contributor-level access or hig...

Jul 16, 2024
CVE-2024-34444
7.1

This CVE describes a Missing Authorization vulnerability in Slider Revolution WordPress plugin that allows unauthenticated attackers to perform unauth...

Jun 19, 2024
CVE-2023-36684
7.1

This CVE describes a missing authorization vulnerability in the WordPress Convert Pro plugin that allows unauthorized users to access administrative f...

Jun 19, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,032 CVEs classified as CWE-862, with 224 rated critical and 842 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free