CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,034)
The WebPurify Profanity Filter WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify plugin setti...
Feb 4, 2026This vulnerability allows authenticated WordPress users with subscriber-level access or higher to manipulate loyalty program rules in the MyRewards pl...
Feb 4, 2026This CVE describes a missing authorization vulnerability in the WP Chill Passster WordPress plugin that allows attackers to bypass content protection ...
Feb 3, 2026This CVE describes a Missing Authorization vulnerability in the Brecht Visual Link Preview WordPress plugin that allows attackers to exploit incorrect...
Feb 3, 2026This CVE describes a missing authorization vulnerability in the Strong Testimonials WordPress plugin that allows attackers to bypass access controls. ...
Feb 3, 2026This vulnerability allows moderators in Discourse to improperly convert private personal messages into public topics, violating user privacy expectati...
Jan 28, 2026This vulnerability in phpMyFAQ allows any authenticated user, regardless of permissions, to trigger configuration backups and retrieve the backup file...
Jan 24, 2026CVE-2026-24139 is an authorization bypass vulnerability in MyTube that allows guest or low-privileged users to download the complete application datab...
Jan 24, 2026The All-in-One Video Gallery WordPress plugin has missing capability checks on AJAX functions, allowing unauthenticated attackers to create and delete...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the Hyyan WooCommerce Polylang Integration plugin for WordPress. It allows attackers to ex...
Jan 23, 2026This CVE describes a missing authorization vulnerability in iNET Webkit WordPress plugin that allows attackers to bypass access controls. It affects a...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the NSquared Simply Schedule Appointments WordPress plugin that allows attackers to bypass...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the designthemes Reservation Plugin (dt-reservation-plugin) for WordPress that allows unau...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Solace WordPress theme that allows attackers to bypass access controls. It affects all...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the WordPress plugin WDV One Page Docs, allowing attackers to bypass access controls and p...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Depicter Slider WordPress plugin that allows attackers to bypass access controls. It a...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Ninja Team GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypa...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Icegram WordPress plugin that allows attackers to bypass access controls. Attackers ca...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the WP BackItUp WordPress plugin that allows attackers to bypass access controls and perfo...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Easy Property Listings WordPress plugin that allows attackers to bypass access control...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the SEO Booster WordPress plugin that allows attackers to exploit incorrectly configured a...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the WANotifier WordPress plugin that allows attackers to exploit incorrectly configured ac...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the WordPress Slider Templates plugin that allows attackers to access functionality not pr...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Payment Gateway Authorize.Net CIM for WooCommerce plugin that allows unauthorized user...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Onepay Sri Lanka payment gateway plugin for WooCommerce. It allows attackers to exploi...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Shown Connector WordPress plugin that allows attackers to change plugin settings witho...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in Event Espresso 4 Decaf WordPress plugin that allows unauthorized users to change plugin se...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in TaxCloud for WooCommerce (simple-sales-tax plugin) that allows attackers to exploit incorr...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Peach Payments Gateway WordPress plugin that allows attackers to bypass access control...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in Tickera's WordPress event ticketing plugin that allows attackers to bypass access controls...
Jan 22, 2026The Wallet System for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or ...
Jan 17, 2026The MailerLite - WooCommerce integration plugin for WordPress has a missing capability check vulnerability that allows authenticated attackers with Su...
Jan 16, 2026This vulnerability allows unauthenticated attackers to demote WordPress administrators to low-privilege roles in the Awesome Support plugin. Attackers...
Jan 16, 2026The WP Page Permalink Extension plugin for WordPress has a missing authorization vulnerability that allows authenticated users with Subscriber-level a...
Jan 9, 2026This vulnerability allows authenticated users in GitLab EE to modify instance-wide AI feature provider settings due to missing authorization checks in...
Jan 9, 2026This CVE describes a Missing Authorization vulnerability in the Munir Kamal Block Slider WordPress plugin that allows attackers to bypass access contr...
Jan 8, 2026This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to enumerate order IDs and access sensitive personal in...
Jan 8, 2026This CVE describes a missing authorization vulnerability in The Plus Addons for Elementor Pro WordPress plugin that allows attackers to bypass access ...
Jan 7, 2026This vulnerability allows unauthenticated attackers to replay form workflow executions in the Bit Form WordPress plugin. Attackers can trigger all con...
Jan 7, 2026This CVE describes a Missing Authorization vulnerability in the Responsive Addons for Elementor WordPress plugin that allows attackers to bypass acces...
Jan 6, 2026This vulnerability in QOCA aim AI Medical Cloud Platform allows authenticated attackers to modify network packet parameters, enabling unauthorized acc...
Jan 5, 2026This authentication bypass vulnerability in Petlibro Smart Pet Feeder Platform allows unauthenticated attackers to access any user account by exploiti...
Jan 4, 2026This CVE describes a missing authorization vulnerability in the BizPrint WordPress plugin that allows attackers to bypass access controls. The vulnera...
Dec 30, 2025CVE-2025-68498 is a missing authorization vulnerability in the Crocoblock JetTabs WordPress plugin that allows attackers to bypass access controls and...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Crocoblock JetBlog WordPress plugin that allows attackers to bypass access controls. A...
Dec 29, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Post Grid and Gutenberg Blocks plugin that allows attackers to bypass access...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'Offload, AI & Optimize with Cloudflare Images' (cf-images). It allow...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the InstaWP Connect WordPress plugin that allows attackers to bypass access controls. Atta...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the RestroPress WordPress plugin that allows attackers to bypass access controls. It affec...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WP Social Ninja WordPress plugin that allows attackers to exploit incorrectly configur...
Dec 18, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,034 CVEs classified as CWE-862, with 225 rated critical and 843 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free