CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,036
Total CVEs
226
Critical
844
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,036)

CVE-2024-13780
6.5

The Hero Mega Menu WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any directory on the ...

Mar 5, 2025
CVE-2025-23763
6.5

This CVE describes a Missing Authorization vulnerability in the WAH Forms WordPress plugin that allows attackers to bypass access controls and access ...

Mar 3, 2025
CVE-2025-23613
6.5

This vulnerability allows unauthorized users to access functionality intended only for authenticated administrators in the WP Journal WordPress plugin...

Mar 3, 2025
CVE-2025-23515
6.5

This CVE describes a Missing Authorization vulnerability in the ts-tree WordPress plugin that allows attackers to delete arbitrary content without pro...

Mar 3, 2025
CVE-2025-26960
6.5

This CVE describes a Missing Authorization vulnerability in the Small Package Quotes – Unishippers Edition WordPress plugin that allows attackers to...

Feb 25, 2025
CVE-2024-37363
6.5

This vulnerability allows unauthorized users to access data sources they shouldn't have permission to view or modify in Hitachi Vantara Pentaho Busine...

Feb 20, 2025
CVE-2025-22289
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'LTL Freight Quotes – Unishippers Edition' that allows attackers to...

Feb 16, 2025
CVE-2025-23766
6.5

This CVE describes a Missing Authorization vulnerability in the OPSI Israel Domestic Shipments WordPress plugin that allows attackers to bypass access...

Feb 14, 2025
CVE-2025-23534
6.5

CVE-2025-23534 is a missing authorization vulnerability in the WPLingo WordPress plugin that allows attackers to delete arbitrary content without prop...

Feb 14, 2025
CVE-2025-26373
6.5

This vulnerability allows authenticated low-privileged attackers to enumerate user accounts in Q-Free MaxTime systems via crafted HTTP requests to the...

Feb 12, 2025
CVE-2025-26376
6.5

This vulnerability allows authenticated low-privileged attackers to modify user data in Q-Free MaxTime systems via crafted HTTP requests. It affects a...

Feb 12, 2025
CVE-2024-3976
6.5

This vulnerability in GitLab allows unauthorized users to view confidential issue titles and descriptions from public projects via the user interface....

Feb 5, 2025
CVE-2025-22730
6.5

This CVE describes a missing authorization vulnerability in the Ksher WordPress payment plugin that allows attackers to bypass access controls. Attack...

Feb 4, 2025
CVE-2025-24697
6.5

This CVE describes a missing authorization vulnerability in the Realwebcare Image Gallery WordPress plugin that allows attackers to bypass access cont...

Feb 3, 2025
CVE-2025-24643
6.5

This CVE describes a Missing Authorization vulnerability in WPGuppy WordPress plugin that allows attackers to bypass access controls. It affects all W...

Feb 3, 2025
CVE-2025-23527
6.5

This CVE describes a Missing Authorization vulnerability in the WC Wallet WordPress plugin that allows attackers to access functionality not properly ...

Feb 3, 2025
CVE-2025-22265
6.5

This CVE describes a Missing Authorization vulnerability in the mgplugin EMI Calculator WordPress plugin that allows attackers to change plugin settin...

Jan 31, 2025
CVE-2025-24143
6.5

This vulnerability allows malicious webpages to bypass file system access restrictions and fingerprint users on Apple devices. It affects macOS, iOS, ...

Jan 27, 2025
CVE-2025-23656
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress Donate visa plugin that allows attackers to inject malicious scripts via sto...

Jan 27, 2025
CVE-2025-23529
6.5

This CVE describes a Missing Authorization vulnerability in the Blokhaus Minterpress WordPress plugin that allows attackers to delete arbitrary conten...

Jan 27, 2025
CVE-2024-13370
6.5

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to update arbitrary plugin options, including setting v...

Jan 25, 2025
CVE-2025-24580
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress 12 Step Meeting List plugin that allows unauthorized users to delete arbitra...

Jan 24, 2025
CVE-2025-24588
6.5

This CVE describes a missing authorization vulnerability in the Patreon WordPress plugin that allows attackers to bypass access controls. It affects W...

Jan 24, 2025
CVE-2024-13698
6.5

The Jobify WordPress theme has missing capability checks that allow unauthenticated attackers to make arbitrary web requests and upload image files. T...

Jan 24, 2025
CVE-2025-23486
6.5

This CVE describes a Missing Authorization vulnerability in the NotFound Database Sync WordPress plugin that allows attackers to bypass access control...

Jan 22, 2025
CVE-2025-24461
6.5

This vulnerability in JetBrains TeamCity allows unauthorized decryption of connection secrets via the Test Connection endpoint. Attackers with access ...

Jan 21, 2025
CVE-2024-50967
EPSS 37.2% 6.5

CVE-2024-50967 is an unauthenticated access control vulnerability in Becon DATAGerry's REST API that allows attackers to remotely query user rights an...

Jan 17, 2025
CVE-2024-13367
6.5

The Sandbox WordPress plugin allows authenticated attackers with Subscriber-level access or higher to download entire sandbox environments containing ...

Jan 17, 2025
CVE-2024-13243
6.5

This CVE describes a Missing Authorization vulnerability in the Drupal Entity Delete Log module that allows attackers to perform forceful browsing to ...

Jan 9, 2025
CVE-2024-11496
6.5

The Infility Global WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify p...

Jan 7, 2025
CVE-2023-40327
6.5

This CVE describes a missing authorization vulnerability in the Putler Connector for WooCommerce plugin that allows unauthenticated attackers to perfo...

Jan 2, 2025
CVE-2023-45633
6.5

This CVE describes a Missing Authorization vulnerability in the IDX IMPress Listings WordPress plugin that allows attackers to bypass access controls....

Jan 2, 2025
CVE-2022-45830
6.5

CVE-2022-45830 is a missing authorization vulnerability in the Analytify WordPress plugin that allows authenticated users with low privileges to perfo...

Jan 2, 2025
CVE-2023-46644
6.5

This CVE describes a Missing Authorization vulnerability in the WP CTA PRO WordPress plugin that allows attackers to exploit incorrectly configured ac...

Jan 2, 2025
CVE-2023-47180
6.5

CVE-2023-47180 is a missing authorization vulnerability in the Finale Lite WordPress plugin that allows attackers to delete arbitrary content without ...

Jan 2, 2025
CVE-2023-46610
6.5

This CVE describes a Missing Authorization vulnerability in the Quill Forms WordPress plugin that allows attackers to exploit incorrectly configured a...

Jan 2, 2025
CVE-2023-46195
6.5

CVE-2023-46195 is a missing authorization vulnerability in the CoSchedule Headline Analyzer WordPress plugin, allowing attackers to bypass access cont...

Jan 2, 2025
CVE-2023-45275
6.5

This vulnerability allows attackers to bypass authorization controls in Kali Forms WordPress plugin, potentially accessing or modifying form data with...

Jan 2, 2025
CVE-2024-56031
6.5

This CVE describes a Missing Authorization vulnerability in the Smart Shopify Product WordPress plugin, allowing unauthorized users to delete arbitrar...

Dec 31, 2024
CVE-2024-12558
6.5

The WP BASE Booking plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or higher to expo...

Dec 21, 2024
CVE-2024-55997
6.5

This CVE describes a Missing Authorization vulnerability in the WordPress 'Order Delivery & Pickup Location Date Time' plugin that allows attackers to...

Dec 18, 2024
CVE-2024-56001
6.5

This CVE describes a Missing Authorization vulnerability in the Ksher WordPress payment plugin that allows attackers to bypass access controls. Attack...

Dec 16, 2024
CVE-2024-12553
6.5

This vulnerability in GeoVision GV-ASManager allows remote attackers to access sensitive information without proper authorization. Attackers can use d...

Dec 13, 2024
CVE-2024-54326
6.5

This CVE describes a missing authorization vulnerability in the GEO my WordPress plugin that allows attackers to bypass access controls. It affects al...

Dec 13, 2024
CVE-2024-54241
6.5

This CVE describes a Missing Authorization vulnerability in the Elite Notification WordPress plugin that allows attackers to exploit incorrectly confi...

Dec 13, 2024
CVE-2023-41664
6.5

This CVE describes a missing authorization vulnerability in the Easy Newsletter Signups WordPress plugin that allows attackers to bypass access contro...

Dec 13, 2024
CVE-2023-37887
6.5

This CVE describes a missing authorization vulnerability in the WPSchoolPress WordPress plugin that allows attackers to bypass access controls. It aff...

Dec 13, 2024
CVE-2023-34019
6.5

This CVE describes a missing authorization vulnerability in the Uncanny Toolkit for LearnDash WordPress plugin that allows attackers to bypass access ...

Dec 13, 2024
CVE-2023-33324
6.5

This vulnerability allows attackers to bypass authorization controls in the Easy Captcha WordPress plugin, potentially accessing administrative functi...

Dec 13, 2024
CVE-2023-33994
6.5

This CVE describes a missing authorization vulnerability in Slimstat Analytics WordPress plugin that allows attackers to bypass access controls. It af...

Dec 13, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free