CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,036
Total CVEs
226
Critical
844
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,036)

CVE-2022-46796
6.5

CVE-2022-46796 is a Missing Authorization vulnerability in VillaTheme CURCY (WooCommerce Multi-Currency) WordPress plugin that allows unauthenticated ...

Dec 13, 2024
CVE-2023-50884
6.5

This CVE describes a Missing Authorization vulnerability in LA-Studio Element Kit for Elementor WordPress plugin. It allows attackers to exploit incor...

Dec 9, 2024
CVE-2023-49848
6.5

This CVE describes a Missing Authorization vulnerability in the Sharkdropship WordPress plugin that allows attackers to bypass access controls. It aff...

Dec 9, 2024
CVE-2023-48779
6.5

This CVE describes a Missing Authorization vulnerability in the 360 Javascript Viewer WordPress plugin that allows attackers to exploit incorrectly co...

Dec 9, 2024
CVE-2023-48274
6.5

This CVE describes a Missing Authorization vulnerability in the Mondial Relay WooCommerce - WCMultiShipping plugin for WordPress. It allows attackers ...

Dec 9, 2024
CVE-2023-47826
6.5

This CVE describes a missing authorization vulnerability in the NicheAddons Restaurant & Cafe Addon for Elementor WordPress plugin. It allows attacker...

Dec 9, 2024
CVE-2023-47764
6.5

This CVE describes a Missing Authorization vulnerability in the Ditty WordPress plugin that allows attackers to bypass access controls. It affects all...

Dec 9, 2024
CVE-2023-32299
6.5

This CVE describes a Missing Authorization vulnerability in the Ni WooCommerce Sales Report WordPress plugin that allows attackers to bypass access co...

Dec 9, 2024
CVE-2023-26522
6.5

This CVE describes a missing authorization vulnerability in the WP Repost WordPress plugin that allows attackers to bypass access controls. Attackers ...

Dec 9, 2024
CVE-2023-25035
6.5

This CVE describes a missing authorization vulnerability in the Fullworks Quick Contact Form WordPress plugin that allows attackers to exploit incorre...

Dec 9, 2024
CVE-2024-53803
6.5

This CVE describes a missing authorization vulnerability in the WP Mailster WordPress plugin that allows attackers to bypass access controls. Attacker...

Dec 6, 2024
CVE-2024-49581
6.5

CVE-2024-49581 is an authorization bypass vulnerability in Palantir Foundry's Object Explorer where users without proper permissions could view restri...

Dec 2, 2024
CVE-2024-10900
6.5

The ProfileGrid WordPress plugin has an authorization vulnerability that allows authenticated users (even with low-privilege subscriber accounts) to d...

Nov 20, 2024
CVE-2024-10717
6.5

The Styler for Ninja Forms WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to d...

Nov 13, 2024
CVE-2024-10294
6.5

The CE21 Suite WordPress plugin up to version 2.2.0 has an authentication bypass vulnerability that allows unauthenticated attackers to modify plugin ...

Nov 9, 2024
CVE-2024-47361
6.5

This CVE describes a Missing Authorization vulnerability in the WPVibes Elementor Addon Elements WordPress plugin. It allows attackers to exploit inco...

Nov 1, 2024
CVE-2024-47308
6.5

This CVE describes a missing authorization vulnerability in the Templately WordPress plugin that allows attackers to access functionality not properly...

Nov 1, 2024
CVE-2024-43979
6.5

This CVE describes a Missing Authorization vulnerability in the Blockbooster WordPress theme that allows attackers to access functionality not properl...

Nov 1, 2024
CVE-2024-43929
6.5

CVE-2024-43929 is a missing authorization vulnerability in the eyecix JobSearch WordPress plugin that allows attackers to access functionality not pro...

Nov 1, 2024
CVE-2024-43310
6.5

This CVE describes a missing authorization vulnerability in the UkrSolution Print Barcode Labels for WooCommerce WordPress plugin. It allows attackers...

Nov 1, 2024
CVE-2024-43209
6.5

This CVE describes a missing authorization vulnerability in the Bitly WordPress plugin that allows attackers to access functionality not properly cons...

Nov 1, 2024
CVE-2024-43122
6.5

This CVE describes a Missing Authorization vulnerability in the Robin Image Optimizer WordPress plugin that allows attackers to exploit incorrectly co...

Nov 1, 2024
CVE-2024-38777
6.5

This CVE describes a Missing Authorization vulnerability in the CreativeMotion Titan Anti-spam & Security WordPress plugin that allows attackers to by...

Nov 1, 2024
CVE-2024-38771
6.5

CVE-2024-38771 is a missing authorization vulnerability in the Atarim WordPress plugin that allows attackers to access functionality not properly cons...

Nov 1, 2024
CVE-2024-37510
6.5

This CVE describes a missing authorization vulnerability in the Charitable WordPress plugin that allows attackers to access functionality not properly...

Nov 1, 2024
CVE-2024-37477
6.5

This CVE describes a missing authorization vulnerability in the WordPress Newspack Content Converter plugin that allows attackers to bypass access con...

Nov 1, 2024
CVE-2024-37209
6.5

This CVE describes a broken access control vulnerability in the Prism IT Systems User Rights Access Manager WordPress plugin. It allows unauthorized u...

Nov 1, 2024
CVE-2024-50424
6.5

This CVE describes a missing authorization vulnerability in the Templately WordPress plugin that allows attackers to bypass access controls. It affect...

Oct 29, 2024
CVE-2024-9829
6.5

The Download Plugin for WordPress has missing capability checks that allow authenticated attackers with Subscriber-level access or higher to download ...

Oct 23, 2024
CVE-2021-4445
6.5

This vulnerability in the Premium Addons for Elementor WordPress plugin allows authenticated attackers with subscriber-level access or higher to modif...

Oct 16, 2024
CVE-2024-9586
6.5

The Linkz.ai WordPress plugin versions up to 1.1.8 contain missing capability checks on the 'check_auth' and 'check_logout' functions, allowing unauth...

Oct 11, 2024
CVE-2024-9161
6.5

The Rank Math SEO WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify or delete metadata. This ...

Oct 5, 2024
CVE-2024-43940
6.5

This vulnerability allows unauthenticated attackers to change plugin settings in the Z Y N I T H WordPress plugin. It affects all WordPress sites runn...

Aug 29, 2024
CVE-2024-7032
6.5

This vulnerability allows unauthenticated attackers to deactivate the Smart Online Order for Clover WordPress plugin and delete all its database table...

Aug 21, 2024
CVE-2024-5940
6.5

The GiveWP WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify event ticket settings when the E...

Aug 20, 2024
CVE-2024-42376
6.5

CVE-2024-42376 is an authorization bypass vulnerability in SAP Shared Service Framework where authenticated users can escalate privileges without prop...

Aug 13, 2024
CVE-2024-6755
6.5

The Social Auto Poster WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary posts. Th...

Jul 24, 2024
CVE-2023-7268
6.5

This vulnerability in the ArtPlacer Widget WordPress plugin allows any authenticated user, including low-privilege subscribers, to delete arbitrary wi...

Jul 19, 2024
CVE-2024-6120
6.5

The Sparkle Demo Importer WordPress plugin has missing capability checks that allow authenticated attackers with Subscriber-level access or higher to ...

Jun 22, 2024
CVE-2023-3204
6.5

The Materialis WordPress theme has an authorization bypass vulnerability that allows authenticated users with minimal permissions (like subscribers) t...

Jun 20, 2024
CVE-2023-37872
6.5

This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WooCommerce Ship to Multiple Addresses WordPress plugin. It al...

Jun 19, 2024
CVE-2023-35050
6.5

CVE-2023-35050 is a missing authorization vulnerability in Elementor Pro WordPress plugin that allows subscribers to perform actions intended only for...

Jun 19, 2024
CVE-2024-1634
6.5

This vulnerability in the Scheduling Plugin – Online Booking for WordPress allows unauthenticated attackers to disconnect the plugin from the startb...

Jun 18, 2024
CVE-2023-51495
6.5

This CVE describes a Missing Authorization vulnerability in the WooCommerce Warranty Requests WordPress plugin. It allows unauthorized users to access...

Jun 14, 2024
CVE-2023-29174
6.5

This CVE describes a Missing Authorization vulnerability in the SKU Label Changer For WooCommerce WordPress plugin. It allows attackers to perform una...

Jun 14, 2024
CVE-2024-34799
6.5

This CVE describes a Missing Authorization vulnerability in the BookingPress WordPress plugin that allows unauthenticated users to manipulate appointm...

Jun 11, 2024
CVE-2024-34820
6.5

This CVE describes a Missing Authorization vulnerability in the If-So Dynamic Content Personalization WordPress plugin. It allows unauthorized users t...

Jun 11, 2024
CVE-2024-35716
6.5

This CVE describes a Missing Authorization vulnerability in the Copymatic WordPress plugin that allows unauthorized users to perform actions intended ...

Jun 11, 2024
CVE-2024-34691
6.5

CVE-2024-34691 is an authorization bypass vulnerability in SAP S/4HANA's Manage Incoming Payment Files (F1680) transaction. Authenticated users can pe...

Jun 11, 2024
CVE-2024-30470
6.5

This CVE describes a Missing Authorization vulnerability in YITH WooCommerce Account Funds Premium plugin for WordPress. It allows attackers to bypass...

Jun 9, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free