CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,036)
CVE-2022-46796 is a Missing Authorization vulnerability in VillaTheme CURCY (WooCommerce Multi-Currency) WordPress plugin that allows unauthenticated ...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in LA-Studio Element Kit for Elementor WordPress plugin. It allows attackers to exploit incor...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Sharkdropship WordPress plugin that allows attackers to bypass access controls. It aff...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the 360 Javascript Viewer WordPress plugin that allows attackers to exploit incorrectly co...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Mondial Relay WooCommerce - WCMultiShipping plugin for WordPress. It allows attackers ...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the NicheAddons Restaurant & Cafe Addon for Elementor WordPress plugin. It allows attacker...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Ditty WordPress plugin that allows attackers to bypass access controls. It affects all...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Ni WooCommerce Sales Report WordPress plugin that allows attackers to bypass access co...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WP Repost WordPress plugin that allows attackers to bypass access controls. Attackers ...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Fullworks Quick Contact Form WordPress plugin that allows attackers to exploit incorre...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WP Mailster WordPress plugin that allows attackers to bypass access controls. Attacker...
Dec 6, 2024CVE-2024-49581 is an authorization bypass vulnerability in Palantir Foundry's Object Explorer where users without proper permissions could view restri...
Dec 2, 2024The ProfileGrid WordPress plugin has an authorization vulnerability that allows authenticated users (even with low-privilege subscriber accounts) to d...
Nov 20, 2024The Styler for Ninja Forms WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to d...
Nov 13, 2024The CE21 Suite WordPress plugin up to version 2.2.0 has an authentication bypass vulnerability that allows unauthenticated attackers to modify plugin ...
Nov 9, 2024This CVE describes a Missing Authorization vulnerability in the WPVibes Elementor Addon Elements WordPress plugin. It allows attackers to exploit inco...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Templately WordPress plugin that allows attackers to access functionality not properly...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Blockbooster WordPress theme that allows attackers to access functionality not properl...
Nov 1, 2024CVE-2024-43929 is a missing authorization vulnerability in the eyecix JobSearch WordPress plugin that allows attackers to access functionality not pro...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the UkrSolution Print Barcode Labels for WooCommerce WordPress plugin. It allows attackers...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Bitly WordPress plugin that allows attackers to access functionality not properly cons...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Robin Image Optimizer WordPress plugin that allows attackers to exploit incorrectly co...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the CreativeMotion Titan Anti-spam & Security WordPress plugin that allows attackers to by...
Nov 1, 2024CVE-2024-38771 is a missing authorization vulnerability in the Atarim WordPress plugin that allows attackers to access functionality not properly cons...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Charitable WordPress plugin that allows attackers to access functionality not properly...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the WordPress Newspack Content Converter plugin that allows attackers to bypass access con...
Nov 1, 2024This CVE describes a broken access control vulnerability in the Prism IT Systems User Rights Access Manager WordPress plugin. It allows unauthorized u...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Templately WordPress plugin that allows attackers to bypass access controls. It affect...
Oct 29, 2024The Download Plugin for WordPress has missing capability checks that allow authenticated attackers with Subscriber-level access or higher to download ...
Oct 23, 2024This vulnerability in the Premium Addons for Elementor WordPress plugin allows authenticated attackers with subscriber-level access or higher to modif...
Oct 16, 2024The Linkz.ai WordPress plugin versions up to 1.1.8 contain missing capability checks on the 'check_auth' and 'check_logout' functions, allowing unauth...
Oct 11, 2024The Rank Math SEO WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify or delete metadata. This ...
Oct 5, 2024This vulnerability allows unauthenticated attackers to change plugin settings in the Z Y N I T H WordPress plugin. It affects all WordPress sites runn...
Aug 29, 2024This vulnerability allows unauthenticated attackers to deactivate the Smart Online Order for Clover WordPress plugin and delete all its database table...
Aug 21, 2024The GiveWP WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify event ticket settings when the E...
Aug 20, 2024CVE-2024-42376 is an authorization bypass vulnerability in SAP Shared Service Framework where authenticated users can escalate privileges without prop...
Aug 13, 2024The Social Auto Poster WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary posts. Th...
Jul 24, 2024This vulnerability in the ArtPlacer Widget WordPress plugin allows any authenticated user, including low-privilege subscribers, to delete arbitrary wi...
Jul 19, 2024The Sparkle Demo Importer WordPress plugin has missing capability checks that allow authenticated attackers with Subscriber-level access or higher to ...
Jun 22, 2024The Materialis WordPress theme has an authorization bypass vulnerability that allows authenticated users with minimal permissions (like subscribers) t...
Jun 20, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WooCommerce Ship to Multiple Addresses WordPress plugin. It al...
Jun 19, 2024CVE-2023-35050 is a missing authorization vulnerability in Elementor Pro WordPress plugin that allows subscribers to perform actions intended only for...
Jun 19, 2024This vulnerability in the Scheduling Plugin – Online Booking for WordPress allows unauthenticated attackers to disconnect the plugin from the startb...
Jun 18, 2024This CVE describes a Missing Authorization vulnerability in the WooCommerce Warranty Requests WordPress plugin. It allows unauthorized users to access...
Jun 14, 2024This CVE describes a Missing Authorization vulnerability in the SKU Label Changer For WooCommerce WordPress plugin. It allows attackers to perform una...
Jun 14, 2024This CVE describes a Missing Authorization vulnerability in the BookingPress WordPress plugin that allows unauthenticated users to manipulate appointm...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the If-So Dynamic Content Personalization WordPress plugin. It allows unauthorized users t...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Copymatic WordPress plugin that allows unauthorized users to perform actions intended ...
Jun 11, 2024CVE-2024-34691 is an authorization bypass vulnerability in SAP S/4HANA's Manage Incoming Payment Files (F1680) transaction. Authenticated users can pe...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in YITH WooCommerce Account Funds Premium plugin for WordPress. It allows attackers to bypass...
Jun 9, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free