CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,034
Total CVEs
225
Critical
843
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,034)

CVE-2026-0572
6.5

The WebPurify Profanity Filter WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify plugin setti...

Feb 4, 2026
CVE-2025-15260
6.5

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to manipulate loyalty program rules in the MyRewards pl...

Feb 4, 2026
CVE-2026-25036
6.5

This CVE describes a missing authorization vulnerability in the WP Chill Passster WordPress plugin that allows attackers to bypass content protection ...

Feb 3, 2026
CVE-2026-24984
6.5

This CVE describes a Missing Authorization vulnerability in the Brecht Visual Link Preview WordPress plugin that allows attackers to exploit incorrect...

Feb 3, 2026
CVE-2026-24957
6.5

This CVE describes a missing authorization vulnerability in the Strong Testimonials WordPress plugin that allows attackers to bypass access controls. ...

Feb 3, 2026
CVE-2026-21865
6.5

This vulnerability allows moderators in Discourse to improperly convert private personal messages into public topics, violating user privacy expectati...

Jan 28, 2026
CVE-2026-24421
6.5

This vulnerability in phpMyFAQ allows any authenticated user, regardless of permissions, to trigger configuration backups and retrieve the backup file...

Jan 24, 2026
CVE-2026-24139
6.5

CVE-2026-24139 is an authorization bypass vulnerability in MyTube that allows guest or low-privileged users to download the complete application datab...

Jan 24, 2026
CVE-2025-14947
6.5

The All-in-One Video Gallery WordPress plugin has missing capability checks on AJAX functions, allowing unauthenticated attackers to create and delete...

Jan 23, 2026
CVE-2026-24585
6.5

This CVE describes a missing authorization vulnerability in the Hyyan WooCommerce Polylang Integration plugin for WordPress. It allows attackers to ex...

Jan 23, 2026
CVE-2026-24566
6.5

This CVE describes a missing authorization vulnerability in iNET Webkit WordPress plugin that allows attackers to bypass access controls. It affects a...

Jan 23, 2026
CVE-2025-69315
6.5

This CVE describes a Missing Authorization vulnerability in the NSquared Simply Schedule Appointments WordPress plugin that allows attackers to bypass...

Jan 22, 2026
CVE-2025-69095
6.5

This CVE describes a Missing Authorization vulnerability in the designthemes Reservation Plugin (dt-reservation-plugin) for WordPress that allows unau...

Jan 22, 2026
CVE-2025-68911
6.5

This CVE describes a missing authorization vulnerability in the Solace WordPress theme that allows attackers to bypass access controls. It affects all...

Jan 22, 2026
CVE-2025-68896
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress plugin WDV One Page Docs, allowing attackers to bypass access controls and p...

Jan 22, 2026
CVE-2025-68558
6.5

This CVE describes a Missing Authorization vulnerability in the Depicter Slider WordPress plugin that allows attackers to bypass access controls. It a...

Jan 22, 2026
CVE-2025-68073
6.5

This CVE describes a missing authorization vulnerability in the Ninja Team GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypa...

Jan 22, 2026
CVE-2025-68507
6.5

This CVE describes a missing authorization vulnerability in the Icegram WordPress plugin that allows attackers to bypass access controls. Attackers ca...

Jan 22, 2026
CVE-2025-68039
6.5

This CVE describes a missing authorization vulnerability in the WP BackItUp WordPress plugin that allows attackers to bypass access controls and perfo...

Jan 22, 2026
CVE-2025-68072
6.5

This CVE describes a Missing Authorization vulnerability in the Easy Property Listings WordPress plugin that allows attackers to bypass access control...

Jan 22, 2026
CVE-2025-68019
6.5

This CVE describes a Missing Authorization vulnerability in the SEO Booster WordPress plugin that allows attackers to exploit incorrectly configured a...

Jan 22, 2026
CVE-2025-68020
6.5

This CVE describes a missing authorization vulnerability in the WANotifier WordPress plugin that allows attackers to exploit incorrectly configured ac...

Jan 22, 2026
CVE-2025-68009
6.5

This CVE describes a missing authorization vulnerability in the WordPress Slider Templates plugin that allows attackers to access functionality not pr...

Jan 22, 2026
CVE-2025-68013
6.5

This CVE describes a Missing Authorization vulnerability in the Payment Gateway Authorize.Net CIM for WooCommerce plugin that allows unauthorized user...

Jan 22, 2026
CVE-2025-68016
6.5

This CVE describes a Missing Authorization vulnerability in the Onepay Sri Lanka payment gateway plugin for WooCommerce. It allows attackers to exploi...

Jan 22, 2026
CVE-2025-68003
6.5

This CVE describes a Missing Authorization vulnerability in the Shown Connector WordPress plugin that allows attackers to change plugin settings witho...

Jan 22, 2026
CVE-2025-68007
6.5

This CVE describes a Missing Authorization vulnerability in Event Espresso 4 Decaf WordPress plugin that allows unauthorized users to change plugin se...

Jan 22, 2026
CVE-2025-67958
6.5

This CVE describes a Missing Authorization vulnerability in TaxCloud for WooCommerce (simple-sales-tax plugin) that allows attackers to exploit incorr...

Jan 22, 2026
CVE-2025-67942
6.5

This CVE describes a missing authorization vulnerability in the Peach Payments Gateway WordPress plugin that allows attackers to bypass access control...

Jan 22, 2026
CVE-2025-67939
6.5

This CVE describes a Missing Authorization vulnerability in Tickera's WordPress event ticketing plugin that allows attackers to bypass access controls...

Jan 22, 2026
CVE-2025-14450
6.5

The Wallet System for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or ...

Jan 17, 2026
CVE-2026-1000
6.5

The MailerLite - WooCommerce integration plugin for WordPress has a missing capability check vulnerability that allows authenticated attackers with Su...

Jan 16, 2026
CVE-2025-12641
6.5

This vulnerability allows unauthenticated attackers to demote WordPress administrators to low-privilege roles in the Awesome Support plugin. Attackers...

Jan 16, 2026
CVE-2025-14172
6.5

The WP Page Permalink Extension plugin for WordPress has a missing authorization vulnerability that allows authenticated users with Subscriber-level a...

Jan 9, 2026
CVE-2025-13781
6.5

This vulnerability allows authenticated users in GitLab EE to modify instance-wide AI feature provider settings due to missing authorization checks in...

Jan 9, 2026
CVE-2026-22522
6.5

This CVE describes a Missing Authorization vulnerability in the Munir Kamal Block Slider WordPress plugin that allows attackers to bypass access contr...

Jan 8, 2026
CVE-2025-13679
6.5

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to enumerate order IDs and access sensitive personal in...

Jan 8, 2026
CVE-2025-46434
6.5

This CVE describes a missing authorization vulnerability in The Plus Addons for Elementor Pro WordPress plugin that allows attackers to bypass access ...

Jan 7, 2026
CVE-2025-14901
6.5

This vulnerability allows unauthenticated attackers to replay form workflow executions in the Bit Form WordPress plugin. Attackers can trigger all con...

Jan 7, 2026
CVE-2025-69363
6.5

This CVE describes a Missing Authorization vulnerability in the Responsive Addons for Elementor WordPress plugin that allows attackers to bypass acces...

Jan 6, 2026
CVE-2025-15235
6.5

This vulnerability in QOCA aim AI Medical Cloud Platform allows authenticated attackers to modify network packet parameters, enabling unauthorized acc...

Jan 5, 2026
CVE-2025-15115
6.5

This authentication bypass vulnerability in Petlibro Smart Pet Feeder Platform allows unauthenticated attackers to access any user account by exploiti...

Jan 4, 2026
CVE-2025-69024
6.5

This CVE describes a missing authorization vulnerability in the BizPrint WordPress plugin that allows attackers to bypass access controls. The vulnera...

Dec 30, 2025
CVE-2025-68498
6.5

CVE-2025-68498 is a missing authorization vulnerability in the Crocoblock JetTabs WordPress plugin that allows attackers to bypass access controls and...

Dec 30, 2025
CVE-2025-68503
6.5

This CVE describes a Missing Authorization vulnerability in the Crocoblock JetBlog WordPress plugin that allows attackers to bypass access controls. A...

Dec 29, 2025
CVE-2025-66058
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress Post Grid and Gutenberg Blocks plugin that allows attackers to bypass access...

Dec 18, 2025
CVE-2025-66104
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'Offload, AI & Optimize with Cloudflare Images' (cf-images). It allow...

Dec 18, 2025
CVE-2025-66068
6.5

This CVE describes a missing authorization vulnerability in the InstaWP Connect WordPress plugin that allows attackers to bypass access controls. Atta...

Dec 18, 2025
CVE-2025-66100
6.5

This CVE describes a missing authorization vulnerability in the RestroPress WordPress plugin that allows attackers to bypass access controls. It affec...

Dec 18, 2025
CVE-2025-64375
6.5

This CVE describes a Missing Authorization vulnerability in the WP Social Ninja WordPress plugin that allows attackers to exploit incorrectly configur...

Dec 18, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,034 CVEs classified as CWE-862, with 225 rated critical and 843 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free