CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,034
Total CVEs
225
Critical
843
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,034)

CVE-2025-63039
6.5

This CVE describes a missing authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. Attackers ...

Dec 18, 2025
CVE-2025-60088
6.5

This CVE describes a Missing Authorization vulnerability in the WebinarIgnition WordPress plugin that allows attackers to bypass access controls. It a...

Dec 18, 2025
CVE-2025-54745
6.5

This CVE describes a Missing Authorization vulnerability in the miniOrange Google Authenticator WordPress plugin, allowing attackers to bypass intende...

Dec 18, 2025
CVE-2025-49902
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress Login Page Customizer plugin that allows attackers to bypass access controls...

Dec 18, 2025
CVE-2025-49041
6.5

This CVE describes a missing authorization vulnerability in the WordPress Get Cash plugin that allows attackers to bypass access controls. Attackers c...

Dec 18, 2025
CVE-2025-14817
6.5

This vulnerability allows third-party Android apps to directly enable ADB debugging on affected Transsion devices without user permission or interacti...

Dec 17, 2025
CVE-2025-13880
6.5

The WP Social Ninja WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view and modify the plugin's a...

Dec 17, 2025
CVE-2025-64520
6.5

This vulnerability allows unauthorized users with API access to read all knowledge base entries in GLPI software. It affects GLPI installations from v...

Dec 16, 2025
CVE-2025-67976
6.5

This CVE describes a missing authorization vulnerability in the Watu Quiz WordPress plugin that allows attackers to bypass access controls. Attackers ...

Dec 16, 2025
CVE-2025-64247
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress Read More & Accordion plugin (expand-maker) that allows attackers to bypass ...

Dec 16, 2025
CVE-2025-66402
6.5

This vulnerability in Misskey allows unauthorized users to export and view posts from favorites or clips they shouldn't have access to. It affects Mis...

Dec 16, 2025
CVE-2025-14508
6.5

The MediaCommander WordPress plugin has an authorization flaw that allows authenticated users with Author-level permissions or higher to delete all fo...

Dec 13, 2025
CVE-2025-14446
6.5

The Popup Builder (Easy Notify Lite) WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-lev...

Dec 13, 2025
CVE-2025-14064
6.5

The BuddyTask WordPress plugin has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or higher to...

Dec 12, 2025
CVE-2025-67560
6.5

This CVE describes a Missing Authorization vulnerability in the Listdom WordPress plugin by Webilia Inc. that allows attackers to bypass access contro...

Dec 9, 2025
CVE-2025-67548
6.5

This CVE describes a missing authorization vulnerability in the WP Delicious delicious-recipes WordPress plugin that allows attackers to bypass access...

Dec 9, 2025
CVE-2025-67540
6.5

This CVE describes a Missing Authorization vulnerability in the Wealcoder Animation Addons for Elementor WordPress plugin that allows attackers to del...

Dec 9, 2025
CVE-2025-63063
6.5

This CVE describes a Missing Authorization vulnerability in the Yandex.Metrica WordPress plugin that allows attackers to exploit incorrectly configure...

Dec 9, 2025
CVE-2025-62090
6.5

This CVE describes a missing authorization vulnerability in the Gutenverse News WordPress plugin that allows attackers to bypass access controls. It a...

Dec 9, 2025
CVE-2025-66079
6.5

This CVE describes a missing authorization vulnerability in the Gutenverse Form WordPress plugin that allows attackers to bypass access controls. It a...

Nov 21, 2025
CVE-2025-10938
6.5

The UiPress Lite WordPress plugin has a vulnerability that allows authenticated attackers with subscriber-level access or higher to extract sensitive ...

Nov 21, 2025
CVE-2025-12174
6.5

This vulnerability in the Directorist WordPress plugin allows authenticated attackers with Subscriber-level access or higher to export listing details...

Nov 19, 2025
CVE-2025-12937
6.5

The ACF Flexible Layouts Manager WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify custom fi...

Nov 18, 2025
CVE-2025-64369
6.5

This CVE describes a missing authorization vulnerability in the Contact Form Email WordPress plugin that allows attackers to bypass access controls. A...

Nov 13, 2025
CVE-2025-64276
6.5

This CVE describes a missing authorization vulnerability in the Ays Pro Survey Maker WordPress plugin that allows attackers to bypass access controls....

Nov 13, 2025
CVE-2025-64259
6.5

This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass access controls. It affec...

Nov 13, 2025
CVE-2025-64261
6.5

This CVE describes a Missing Authorization vulnerability in the Appointment Booking Calendar WordPress plugin that allows attackers to bypass access c...

Nov 13, 2025
CVE-2025-64402
6.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where documents containing OLE objects with external links can au...

Nov 12, 2025
CVE-2025-7663
6.5

The Ovatheme Events Manager WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to perform administrat...

Nov 8, 2025
CVE-2025-4522
6.5

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary user accounts, including administra...

Nov 7, 2025
CVE-2025-62033
6.5

This CVE describes a missing authorization (broken access control) vulnerability in the uxper Togo WordPress theme. It allows attackers to access func...

Nov 6, 2025
CVE-2025-60247
6.5

This CVE describes a Missing Authorization vulnerability in the Bux Woocommerce plugin for WordPress, allowing attackers to access functionality not p...

Nov 6, 2025
CVE-2025-58986
6.5

This CVE describes a Missing Authorization vulnerability in the Jock On Air Now (JOAN) WordPress plugin that allows attackers to bypass access control...

Nov 6, 2025
CVE-2025-63294
6.5

CVE-2025-63294 is an insecure permissions vulnerability in WorkDo HRM SaaS HR and Payroll Tool 8.1 that allows authenticated users to create leave or ...

Nov 4, 2025
CVE-2025-11758
6.5

The All in One Time Clock Lite WordPress plugin up to version 2.0.3 allows unauthenticated attackers to perform admin-level actions due to missing aut...

Nov 4, 2025
CVE-2025-63293
6.5

This vulnerability allows authenticated users to append comments or upload attachments to tickets they are not authorized to view or edit in FairSketc...

Nov 3, 2025
CVE-2013-10072
6.5

Nagios XI versions before 2012R1.6 have an authorization flaw in Auto-Discovery functionality. Users with read-only permissions can access Auto-Discov...

Oct 30, 2025
CVE-2025-11705
6.5

This vulnerability in the Anti-Malware Security and Brute-Force Firewall WordPress plugin allows authenticated attackers with Subscriber-level access ...

Oct 29, 2025
CVE-2025-62247
6.5

This vulnerability allows authenticated users in Liferay Portal/DXP to access and select unauthorized Blueprints through Collection Providers across i...

Oct 22, 2025
CVE-2025-48096
6.5

This CVE describes a missing authorization vulnerability in the FRESHFACE Custom CSS WordPress plugin that allows attackers to bypass access controls....

Oct 22, 2025
CVE-2025-11372
6.5

This vulnerability in the LearnPress WordPress LMS plugin allows unauthenticated attackers to perform destructive database operations via REST API end...

Oct 18, 2025
CVE-2025-9549
6.5

A missing authorization vulnerability in Drupal Facets allows attackers to access restricted content through forceful browsing. This affects Drupal si...

Oct 10, 2025
CVE-2025-60098
6.5

This CVE describes a missing authorization vulnerability in the Theme My Login WordPress plugin that allows attackers to bypass access controls. Attac...

Sep 26, 2025
CVE-2025-59581
6.5

This CVE describes a Missing Authorization vulnerability in VW THEMES Ibtana WordPress plugin that allows attackers to delete arbitrary content withou...

Sep 22, 2025
CVE-2025-59576
6.5

This CVE describes a missing authorization vulnerability in the MasterStudy LMS WordPress plugin that allows attackers to bypass access controls and p...

Sep 22, 2025
CVE-2025-58678
6.5

A missing authorization vulnerability in the PickPlugins Accordion WordPress plugin allows attackers to bypass intended access controls. This affects ...

Sep 22, 2025
CVE-2025-58680
6.5

This CVE describes a Missing Authorization vulnerability in the Gutentor WordPress plugin that allows attackers to exploit incorrectly configured acce...

Sep 22, 2025
CVE-2025-57955
6.5

This CVE describes a missing authorization vulnerability in the Post Carousel Slider for Elementor WordPress plugin. Attackers can exploit incorrectly...

Sep 22, 2025
CVE-2025-57909
6.5

This CVE describes a missing authorization vulnerability in the WordPress Editor Custom Color Palette plugin that allows attackers to bypass access co...

Sep 22, 2025
CVE-2025-59413
6.5

CubeCart versions before 6.5.11 contain a logic flaw in the newsletter subscription endpoint that allows attackers to unsubscribe any user without con...

Sep 22, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,034 CVEs classified as CWE-862, with 225 rated critical and 843 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free