CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,036)
This CVE describes a Missing Authorization vulnerability in the WordPress AJAX Hits Counter + Popular Posts Widget plugin. It allows attackers to expl...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in WisdmLabs Edwiser Bridge WordPress plugin that allows attackers to bypass access controls ...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Cloudinary WordPress plugin that allows attackers to bypass access controls. It affect...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the FluentBoards WordPress plugin that allows attackers to exploit incorrectly configured ...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Monetag Official WordPress plugin that allows attackers to exploit incorrectly configu...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the WordPress Integrate Google Drive plugin that allows attackers to bypass access control...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Premium Addons for Elementor WordPress plugin that allows attackers to change plugin s...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the merkulove Scroller WordPress plugin that allows attackers to bypass access controls. I...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Comparimager for Elementor WordPress plugin that allows attackers to bypass access con...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the merkulove Crumber Elementor WordPress plugin that allows attackers to exploit incorrec...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Audier For Elementor WordPress plugin that allows attackers to exploit incorrectly con...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Uper for Elementor WordPress plugin that allows attackers to exploit incorrectly confi...
Jan 22, 2026This vulnerability allows authenticated WordPress users with subscriber-level access or higher to delete arbitrary attachments on sites running vulner...
Jan 20, 2026The Events Calendar WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher ...
Jan 20, 2026The Image Photo Gallery Final Tiles Grid WordPress plugin has insufficient access controls on AJAX endpoints, allowing authenticated users with Contri...
Jan 20, 2026CrawlChat versions before 0.0.8 lack proper permission checks for Discord bot commands, allowing any Discord guild member to inject malicious content ...
Jan 19, 2026The WP-CRM System WordPress plugin has missing capability checks on two AJAX functions, allowing authenticated users with subscriber-level access or h...
Jan 14, 2026The WP Duplicate Page WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level access or high...
Jan 13, 2026This CVE describes a Missing Authorization vulnerability in the LPagery WordPress plugin that allows attackers to bypass access controls. Attackers ca...
Jan 8, 2026This CVE describes a Missing Authorization vulnerability in the GA4WP: Google Analytics for WordPress plugin that allows attackers to exploit incorrec...
Jan 8, 2026The aBlocks WordPress plugin has missing capability checks on AJAX actions, allowing authenticated attackers with subscriber-level access to read sens...
Jan 7, 2026This CVE describes a Missing Authorization vulnerability in the WPCenter AffiliateX WordPress plugin that allows attackers to exploit incorrectly conf...
Jan 6, 2026This CVE describes a missing authorization vulnerability in the CoolHappy The Events Calendar Countdown Addon for WordPress. It allows attackers to ex...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in the Fahad Mahmood RSS Feed Widget WordPress plugin that allows attackers to exploit incorr...
Jan 6, 2026This CVE describes a missing authorization vulnerability in StellarWP's The Events Calendar WordPress plugin that allows attackers to bypass intended ...
Jan 6, 2026This CVE describes a missing authorization vulnerability in the WordPress Proxy & VPN Blocker plugin that allows attackers to bypass access controls. ...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in the Better Business Reviews WordPress plugin that allows attackers to exploit incorrectly ...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in the WeDesignTech Ultimate Booking Addon WordPress plugin that allows attackers to bypass a...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in BoldGrid Post and Page Builder WordPress plugin that allows attackers to bypass access con...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in the Worker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Worker for WPBakery WordPress plugin that allows attackers to bypass access controls. ...
Dec 31, 2025A missing authorization vulnerability in the Logger for Elementor WordPress plugin allows attackers to bypass access controls and potentially view or ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Conformer for Elementor WordPress plugin that allows attackers to bypass intended acce...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the merkulove UnGrabber WordPress plugin that allows attackers to bypass access controls. ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the merkulove Appender WordPress plugin that allows attackers to exploit incorrectly confi...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the Countdowner for Elementor WordPress plugin that allows attackers to bypass access cont...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the merkulove Criptopayer for Elementor WordPress plugin that allows attackers to exploit ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Headinger for Elementor WordPress plugin that allows attackers to exploit incorrectly ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Gmaper for Elementor WordPress plugin that allows attackers to bypass intended access ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Walker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Select Graphist for Elementor WordPress plugin that allows attackers to exploit incorr...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Questionar for Elementor WordPress plugin that allows attackers to bypass intended acc...
Dec 31, 2025CVE-2025-66156 is a missing authorization vulnerability in the Watcher for Elementor WordPress plugin that allows attackers to bypass access controls ...
Dec 31, 2025A missing authorization vulnerability in the merkulove Slider for Elementor WordPress plugin allows attackers to bypass intended access controls. This...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Couponer for Elementor WordPress plugin that allows attackers to exploit incorrectly c...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the WP Attachments WordPress plugin that allows attackers to bypass intended access contro...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Vollstart Serial Codes Generator and Validator with WooCommerce Support WordPress plug...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Totalsoft Portfolio Gallery WordPress plugin that allows attackers to bypass access co...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the SaifuMak Add Custom Codes WordPress plugin that allows attackers to bypass access cont...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Core Web Vitals & PageSpeed Booster plugin that allows attackers to exploit ...
Dec 31, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free