CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,036)
The Hero Mega Menu WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any directory on the ...
Mar 5, 2025This CVE describes a Missing Authorization vulnerability in the WAH Forms WordPress plugin that allows attackers to bypass access controls and access ...
Mar 3, 2025This vulnerability allows unauthorized users to access functionality intended only for authenticated administrators in the WP Journal WordPress plugin...
Mar 3, 2025This CVE describes a Missing Authorization vulnerability in the ts-tree WordPress plugin that allows attackers to delete arbitrary content without pro...
Mar 3, 2025This CVE describes a Missing Authorization vulnerability in the Small Package Quotes – Unishippers Edition WordPress plugin that allows attackers to...
Feb 25, 2025This vulnerability allows unauthorized users to access data sources they shouldn't have permission to view or modify in Hitachi Vantara Pentaho Busine...
Feb 20, 2025This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'LTL Freight Quotes – Unishippers Edition' that allows attackers to...
Feb 16, 2025This CVE describes a Missing Authorization vulnerability in the OPSI Israel Domestic Shipments WordPress plugin that allows attackers to bypass access...
Feb 14, 2025CVE-2025-23534 is a missing authorization vulnerability in the WPLingo WordPress plugin that allows attackers to delete arbitrary content without prop...
Feb 14, 2025This vulnerability allows authenticated low-privileged attackers to enumerate user accounts in Q-Free MaxTime systems via crafted HTTP requests to the...
Feb 12, 2025This vulnerability allows authenticated low-privileged attackers to modify user data in Q-Free MaxTime systems via crafted HTTP requests. It affects a...
Feb 12, 2025This vulnerability in GitLab allows unauthorized users to view confidential issue titles and descriptions from public projects via the user interface....
Feb 5, 2025This CVE describes a missing authorization vulnerability in the Ksher WordPress payment plugin that allows attackers to bypass access controls. Attack...
Feb 4, 2025This CVE describes a missing authorization vulnerability in the Realwebcare Image Gallery WordPress plugin that allows attackers to bypass access cont...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in WPGuppy WordPress plugin that allows attackers to bypass access controls. It affects all W...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in the WC Wallet WordPress plugin that allows attackers to access functionality not properly ...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in the mgplugin EMI Calculator WordPress plugin that allows attackers to change plugin settin...
Jan 31, 2025This vulnerability allows malicious webpages to bypass file system access restrictions and fingerprint users on Apple devices. It affects macOS, iOS, ...
Jan 27, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Donate visa plugin that allows attackers to inject malicious scripts via sto...
Jan 27, 2025This CVE describes a Missing Authorization vulnerability in the Blokhaus Minterpress WordPress plugin that allows attackers to delete arbitrary conten...
Jan 27, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to update arbitrary plugin options, including setting v...
Jan 25, 2025This CVE describes a Missing Authorization vulnerability in the WordPress 12 Step Meeting List plugin that allows unauthorized users to delete arbitra...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the Patreon WordPress plugin that allows attackers to bypass access controls. It affects W...
Jan 24, 2025The Jobify WordPress theme has missing capability checks that allow unauthenticated attackers to make arbitrary web requests and upload image files. T...
Jan 24, 2025This CVE describes a Missing Authorization vulnerability in the NotFound Database Sync WordPress plugin that allows attackers to bypass access control...
Jan 22, 2025This vulnerability in JetBrains TeamCity allows unauthorized decryption of connection secrets via the Test Connection endpoint. Attackers with access ...
Jan 21, 2025CVE-2024-50967 is an unauthenticated access control vulnerability in Becon DATAGerry's REST API that allows attackers to remotely query user rights an...
Jan 17, 2025The Sandbox WordPress plugin allows authenticated attackers with Subscriber-level access or higher to download entire sandbox environments containing ...
Jan 17, 2025This CVE describes a Missing Authorization vulnerability in the Drupal Entity Delete Log module that allows attackers to perform forceful browsing to ...
Jan 9, 2025The Infility Global WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify p...
Jan 7, 2025This CVE describes a missing authorization vulnerability in the Putler Connector for WooCommerce plugin that allows unauthenticated attackers to perfo...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the IDX IMPress Listings WordPress plugin that allows attackers to bypass access controls....
Jan 2, 2025CVE-2022-45830 is a missing authorization vulnerability in the Analytify WordPress plugin that allows authenticated users with low privileges to perfo...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the WP CTA PRO WordPress plugin that allows attackers to exploit incorrectly configured ac...
Jan 2, 2025CVE-2023-47180 is a missing authorization vulnerability in the Finale Lite WordPress plugin that allows attackers to delete arbitrary content without ...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the Quill Forms WordPress plugin that allows attackers to exploit incorrectly configured a...
Jan 2, 2025CVE-2023-46195 is a missing authorization vulnerability in the CoSchedule Headline Analyzer WordPress plugin, allowing attackers to bypass access cont...
Jan 2, 2025This vulnerability allows attackers to bypass authorization controls in Kali Forms WordPress plugin, potentially accessing or modifying form data with...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the Smart Shopify Product WordPress plugin, allowing unauthorized users to delete arbitrar...
Dec 31, 2024The WP BASE Booking plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or higher to expo...
Dec 21, 2024This CVE describes a Missing Authorization vulnerability in the WordPress 'Order Delivery & Pickup Location Date Time' plugin that allows attackers to...
Dec 18, 2024This CVE describes a Missing Authorization vulnerability in the Ksher WordPress payment plugin that allows attackers to bypass access controls. Attack...
Dec 16, 2024This vulnerability in GeoVision GV-ASManager allows remote attackers to access sensitive information without proper authorization. Attackers can use d...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the GEO my WordPress plugin that allows attackers to bypass access controls. It affects al...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the Elite Notification WordPress plugin that allows attackers to exploit incorrectly confi...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Easy Newsletter Signups WordPress plugin that allows attackers to bypass access contro...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the WPSchoolPress WordPress plugin that allows attackers to bypass access controls. It aff...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Uncanny Toolkit for LearnDash WordPress plugin that allows attackers to bypass access ...
Dec 13, 2024This vulnerability allows attackers to bypass authorization controls in the Easy Captcha WordPress plugin, potentially accessing administrative functi...
Dec 13, 2024This CVE describes a missing authorization vulnerability in Slimstat Analytics WordPress plugin that allows attackers to bypass access controls. It af...
Dec 13, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free