CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,035)
CubeCart versions before 6.5.11 contain a logic flaw in the newsletter subscription endpoint that allows attackers to unsubscribe any user without con...
Sep 22, 2025Mattermost versions 10.10.x through 10.10.1 fail to properly sanitize user data during shared channel synchronization, allowing malicious remote clust...
Sep 15, 2025CVE-2025-39541 is a missing authorization vulnerability in the WP Simple Booking Calendar WordPress plugin that allows attackers to perform unauthoriz...
Sep 9, 2025CVE-2025-42912 is an authorization bypass vulnerability in SAP HCM My Timesheet Fiori 2.0 that allows authenticated users to perform unauthorized acti...
Sep 9, 2025This CVE describes a missing authorization vulnerability in the VillaTheme HAPPY WordPress plugin that allows attackers to bypass access controls. It ...
Sep 5, 2025This CVE describes a missing authorization vulnerability in the Stylemix MasterStudy LMS WordPress plugin that allows attackers to bypass access contr...
Sep 5, 2025The AI Engine WordPress plugin up to version 2.9.5 lacks proper authentication checks in its REST API endpoints, allowing unauthenticated attackers to...
Sep 3, 2025CVE-2025-58616 is a missing authorization vulnerability in Frisbii Pay WordPress plugin that allows attackers to bypass access controls and potentiall...
Sep 3, 2025This vulnerability allows attackers to bypass authorization controls in the All Bootstrap Blocks WordPress plugin, potentially accessing or modifying ...
Aug 28, 2025This CVE describes a missing authorization vulnerability in the Houzez CRM WordPress plugin that allows attackers to bypass access controls. It affect...
Aug 28, 2025This CVE describes a missing authorization vulnerability in the Mojoomla School Management WordPress plugin that allows attackers to bypass access con...
Aug 26, 2025This CVE describes an authorization bypass vulnerability in flaskBlog where admin role checks are only performed on the main /admin route but not on s...
Aug 19, 2025This CVE describes a Missing Authorization vulnerability in The Plus Addons for Elementor Page Builder Lite WordPress plugin that allows attackers to ...
Aug 14, 2025This vulnerability allows an authenticated low-privileged remote attacker to bypass authorization and access troubleshoot files from different domains...
Aug 14, 2025This CVE describes a Missing Authorization vulnerability in the DB Backup WordPress plugin that allows attackers to exploit incorrectly configured acc...
Aug 14, 2025This vulnerability allows authenticated remote attackers to reset administrator passwords in Ivanti Virtual Application Delivery Controller (vADC) adm...
Aug 12, 2025This vulnerability in the Malcure Malware Scanner WordPress plugin allows authenticated attackers with subscriber-level access or higher to read arbit...
Jul 18, 2025This CVE describes a missing authorization vulnerability in WPFactory's Product XML Feed Manager for WooCommerce plugin. It allows attackers to exploi...
Jul 16, 2025This vulnerability in Conjur secrets management software allows authenticated attackers to inject unauthorized resources into the database and bypass ...
Jul 15, 2025This CVE describes a missing authorization vulnerability in the VG WORT METIS WordPress plugin that allows attackers to bypass access controls. Attack...
Jul 4, 2025This CVE describes a missing authorization vulnerability in the pankaj.sakaria CMS Blocks WordPress plugin that allows attackers to bypass intended ac...
Jun 27, 2025This CVE describes a Missing Authorization vulnerability in the WP Dummy Content Generator WordPress plugin that allows attackers to delete arbitrary ...
Jun 17, 2025This CVE describes a Missing Authorization vulnerability in Drupal's Bookable Calendar module that allows attackers to access restricted functionality...
Jun 13, 2025This CVE describes a Missing Authorization vulnerability in the StyleAI WordPress plugin that allows attackers to access functionality not properly re...
Jun 9, 2025This CVE describes a Missing Authorization vulnerability in Woo Slider Pro WordPress plugin that allows attackers to delete arbitrary slider content w...
May 30, 2025This CVE describes a Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce WordPress plugin. It allows attackers to...
May 19, 2025This CVE describes a Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal that allows forceful browsing. Attackers can bypass...
May 14, 2025An authenticated user without proper permissions can view other users' account information in affected software. This information disclosure vulnerabi...
May 12, 2025This CVE describes a Missing Authorization vulnerability in the RelyWP AI Text to Speech WordPress plugin that allows attackers to bypass access contr...
Apr 17, 2025This CVE describes a missing authorization vulnerability in WP Helper Premium plugin that allows attackers to access functionality not properly constr...
Apr 17, 2025This CVE describes a missing authorization vulnerability in the FADI MED Editor Wysiwyg Background Color WordPress plugin that allows attackers to byp...
Apr 17, 2025This CVE describes a Missing Authorization vulnerability in the Themefic Instantio WordPress plugin that allows attackers to change plugin settings wi...
Apr 17, 2025This CVE describes a Missing Authorization vulnerability in the WordPress 'Delete All Posts' plugin that allows attackers to delete all posts without ...
Apr 17, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Internal Link Optimiser plugin that allows attackers to change plugin settin...
Apr 10, 2025This CVE describes a missing authorization vulnerability in the WordPress Site Notify plugin that allows attackers to bypass access controls. Attacker...
Apr 10, 2025This CVE describes a missing authorization vulnerability in the Specia Companion WordPress plugin that allows attackers to bypass access controls. Att...
Apr 10, 2025This CVE describes a Missing Authorization vulnerability in the Shiptrack Booking Calendar and Notification WordPress plugin that allows attackers to ...
Apr 4, 2025This CVE describes a Missing Authorization vulnerability in Eniture Technology's Pallet Packaging for WooCommerce plugin that allows attackers to bypa...
Apr 4, 2025CVE-2025-31858 is a missing authorization vulnerability in the Local Magic WordPress plugin that allows attackers to bypass access controls and perfor...
Apr 3, 2025This CVE describes a Missing Authorization vulnerability in the OTWthemes Widget Manager Light WordPress plugin that allows attackers to access functi...
Apr 3, 2025CVE-2025-31736 is a missing authorization vulnerability in the richtexteditor WordPress plugin that allows attackers to bypass access controls and per...
Apr 3, 2025This CVE describes a missing authorization vulnerability in the TuriTop Booking System WordPress plugin that allows attackers to bypass access control...
Apr 3, 2025This CVE describes a Missing Authorization vulnerability in the Residential Address Detection WordPress plugin that allows attackers to bypass access ...
Apr 3, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Append Content plugin that allows attackers to change plugin settings withou...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the Blocksera Cryptocurrency Widgets Pack WordPress plugin that allows attackers to bypass...
Mar 31, 2025This vulnerability allows unauthorized users to create or modify checklists in lunary-ai/lunary, bypassing permission checks. Attackers can also spoof...
Mar 20, 2025In lunary-ai/lunary version 1.5.6, the /v1/evaluators/ endpoint lacks proper access control, allowing any authenticated user associated with a project...
Mar 20, 2025The GiveWP WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to access sensitive earnings report data. This af...
Mar 15, 2025This vulnerability in the WC Affiliate WordPress plugin allows authenticated attackers with Subscriber-level access or higher to export sensitive affi...
Mar 15, 2025The Hero Mega Menu WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any directory on the ...
Mar 5, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,035 CVEs classified as CWE-862, with 225 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free