CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,034)
This CVE describes a missing authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. Attackers ...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WebinarIgnition WordPress plugin that allows attackers to bypass access controls. It a...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the miniOrange Google Authenticator WordPress plugin, allowing attackers to bypass intende...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Login Page Customizer plugin that allows attackers to bypass access controls...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the WordPress Get Cash plugin that allows attackers to bypass access controls. Attackers c...
Dec 18, 2025This vulnerability allows third-party Android apps to directly enable ADB debugging on affected Transsion devices without user permission or interacti...
Dec 17, 2025The WP Social Ninja WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view and modify the plugin's a...
Dec 17, 2025This vulnerability allows unauthorized users with API access to read all knowledge base entries in GLPI software. It affects GLPI installations from v...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Watu Quiz WordPress plugin that allows attackers to bypass access controls. Attackers ...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Read More & Accordion plugin (expand-maker) that allows attackers to bypass ...
Dec 16, 2025This vulnerability in Misskey allows unauthorized users to export and view posts from favorites or clips they shouldn't have access to. It affects Mis...
Dec 16, 2025The MediaCommander WordPress plugin has an authorization flaw that allows authenticated users with Author-level permissions or higher to delete all fo...
Dec 13, 2025The Popup Builder (Easy Notify Lite) WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-lev...
Dec 13, 2025The BuddyTask WordPress plugin has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or higher to...
Dec 12, 2025This CVE describes a Missing Authorization vulnerability in the Listdom WordPress plugin by Webilia Inc. that allows attackers to bypass access contro...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WP Delicious delicious-recipes WordPress plugin that allows attackers to bypass access...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Wealcoder Animation Addons for Elementor WordPress plugin that allows attackers to del...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Yandex.Metrica WordPress plugin that allows attackers to exploit incorrectly configure...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Gutenverse News WordPress plugin that allows attackers to bypass access controls. It a...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Gutenverse Form WordPress plugin that allows attackers to bypass access controls. It a...
Nov 21, 2025The UiPress Lite WordPress plugin has a vulnerability that allows authenticated attackers with subscriber-level access or higher to extract sensitive ...
Nov 21, 2025This vulnerability in the Directorist WordPress plugin allows authenticated attackers with Subscriber-level access or higher to export listing details...
Nov 19, 2025The ACF Flexible Layouts Manager WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify custom fi...
Nov 18, 2025This CVE describes a missing authorization vulnerability in the Contact Form Email WordPress plugin that allows attackers to bypass access controls. A...
Nov 13, 2025This CVE describes a missing authorization vulnerability in the Ays Pro Survey Maker WordPress plugin that allows attackers to bypass access controls....
Nov 13, 2025This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass access controls. It affec...
Nov 13, 2025This CVE describes a Missing Authorization vulnerability in the Appointment Booking Calendar WordPress plugin that allows attackers to bypass access c...
Nov 13, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where documents containing OLE objects with external links can au...
Nov 12, 2025The Ovatheme Events Manager WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to perform administrat...
Nov 8, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary user accounts, including administra...
Nov 7, 2025This CVE describes a missing authorization (broken access control) vulnerability in the uxper Togo WordPress theme. It allows attackers to access func...
Nov 6, 2025This CVE describes a Missing Authorization vulnerability in the Bux Woocommerce plugin for WordPress, allowing attackers to access functionality not p...
Nov 6, 2025This CVE describes a Missing Authorization vulnerability in the Jock On Air Now (JOAN) WordPress plugin that allows attackers to bypass access control...
Nov 6, 2025CVE-2025-63294 is an insecure permissions vulnerability in WorkDo HRM SaaS HR and Payroll Tool 8.1 that allows authenticated users to create leave or ...
Nov 4, 2025The All in One Time Clock Lite WordPress plugin up to version 2.0.3 allows unauthenticated attackers to perform admin-level actions due to missing aut...
Nov 4, 2025This vulnerability allows authenticated users to append comments or upload attachments to tickets they are not authorized to view or edit in FairSketc...
Nov 3, 2025Nagios XI versions before 2012R1.6 have an authorization flaw in Auto-Discovery functionality. Users with read-only permissions can access Auto-Discov...
Oct 30, 2025This vulnerability in the Anti-Malware Security and Brute-Force Firewall WordPress plugin allows authenticated attackers with Subscriber-level access ...
Oct 29, 2025This vulnerability allows authenticated users in Liferay Portal/DXP to access and select unauthorized Blueprints through Collection Providers across i...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the FRESHFACE Custom CSS WordPress plugin that allows attackers to bypass access controls....
Oct 22, 2025This vulnerability in the LearnPress WordPress LMS plugin allows unauthenticated attackers to perform destructive database operations via REST API end...
Oct 18, 2025A missing authorization vulnerability in Drupal Facets allows attackers to access restricted content through forceful browsing. This affects Drupal si...
Oct 10, 2025This CVE describes a missing authorization vulnerability in the Theme My Login WordPress plugin that allows attackers to bypass access controls. Attac...
Sep 26, 2025This CVE describes a Missing Authorization vulnerability in VW THEMES Ibtana WordPress plugin that allows attackers to delete arbitrary content withou...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the MasterStudy LMS WordPress plugin that allows attackers to bypass access controls and p...
Sep 22, 2025A missing authorization vulnerability in the PickPlugins Accordion WordPress plugin allows attackers to bypass intended access controls. This affects ...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in the Gutentor WordPress plugin that allows attackers to exploit incorrectly configured acce...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Post Carousel Slider for Elementor WordPress plugin. Attackers can exploit incorrectly...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the WordPress Editor Custom Color Palette plugin that allows attackers to bypass access co...
Sep 22, 2025CubeCart versions before 6.5.11 contain a logic flaw in the newsletter subscription endpoint that allows attackers to unsubscribe any user without con...
Sep 22, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,034 CVEs classified as CWE-862, with 225 rated critical and 843 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free