CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,036
Total CVEs
226
Critical
844
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,036)

CVE-2026-24587
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress AJAX Hits Counter + Popular Posts Widget plugin. It allows attackers to expl...

Jan 23, 2026
CVE-2026-24570
5.4

This CVE describes a Missing Authorization vulnerability in WisdmLabs Edwiser Bridge WordPress plugin that allows attackers to bypass access controls ...

Jan 23, 2026
CVE-2026-24560
5.4

This CVE describes a Missing Authorization vulnerability in the Cloudinary WordPress plugin that allows attackers to bypass access controls. It affect...

Jan 23, 2026
CVE-2026-24561
5.4

This CVE describes a Missing Authorization vulnerability in the FluentBoards WordPress plugin that allows attackers to exploit incorrectly configured ...

Jan 23, 2026
CVE-2026-24551
5.4

This CVE describes a Missing Authorization vulnerability in the Monetag Official WordPress plugin that allows attackers to exploit incorrectly configu...

Jan 23, 2026
CVE-2026-24540
5.4

This CVE describes a missing authorization vulnerability in the WordPress Integrate Google Drive plugin that allows attackers to bypass access control...

Jan 23, 2026
CVE-2025-69300
5.4

This CVE describes a Missing Authorization vulnerability in the Premium Addons for Elementor WordPress plugin that allows attackers to change plugin s...

Jan 22, 2026
CVE-2025-66141
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Scroller WordPress plugin that allows attackers to bypass access controls. I...

Jan 22, 2026
CVE-2025-66142
5.4

This CVE describes a Missing Authorization vulnerability in the Comparimager for Elementor WordPress plugin that allows attackers to bypass access con...

Jan 22, 2026
CVE-2025-66143
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Crumber Elementor WordPress plugin that allows attackers to exploit incorrec...

Jan 22, 2026
CVE-2025-66139
5.4

This CVE describes a Missing Authorization vulnerability in the Audier For Elementor WordPress plugin that allows attackers to exploit incorrectly con...

Jan 22, 2026
CVE-2025-66140
5.4

This CVE describes a Missing Authorization vulnerability in the Uper for Elementor WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 22, 2026
CVE-2026-0548
5.4

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to delete arbitrary attachments on sites running vulner...

Jan 20, 2026
CVE-2025-15043
5.4

The Events Calendar WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher ...

Jan 20, 2026
CVE-2025-15466
5.4

The Image Photo Gallery Final Tiles Grid WordPress plugin has insufficient access controls on AJAX endpoints, allowing authenticated users with Contri...

Jan 20, 2026
CVE-2026-23875
5.4

CrawlChat versions before 0.0.8 lack proper permission checks for Discord bot commands, allowing any Discord guild member to inject malicious content ...

Jan 19, 2026
CVE-2025-14854
5.4

The WP-CRM System WordPress plugin has missing capability checks on two AJAX functions, allowing authenticated users with subscriber-level access or h...

Jan 14, 2026
CVE-2025-14001
5.4

The WP Duplicate Page WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level access or high...

Jan 13, 2026
CVE-2026-22490
5.4

This CVE describes a Missing Authorization vulnerability in the LPagery WordPress plugin that allows attackers to bypass access controls. Attackers ca...

Jan 8, 2026
CVE-2026-22517
5.4

This CVE describes a Missing Authorization vulnerability in the GA4WP: Google Analytics for WordPress plugin that allows attackers to exploit incorrec...

Jan 8, 2026
CVE-2025-12449
5.4

The aBlocks WordPress plugin has missing capability checks on AJAX actions, allowing authenticated attackers with subscriber-level access to read sens...

Jan 7, 2026
CVE-2025-69346
5.4

This CVE describes a Missing Authorization vulnerability in the WPCenter AffiliateX WordPress plugin that allows attackers to exploit incorrectly conf...

Jan 6, 2026
CVE-2025-69348
5.4

This CVE describes a missing authorization vulnerability in the CoolHappy The Events Calendar Countdown Addon for WordPress. It allows attackers to ex...

Jan 6, 2026
CVE-2025-69349
5.4

This CVE describes a Missing Authorization vulnerability in the Fahad Mahmood RSS Feed Widget WordPress plugin that allows attackers to exploit incorr...

Jan 6, 2026
CVE-2025-69352
5.4

This CVE describes a missing authorization vulnerability in StellarWP's The Events Calendar WordPress plugin that allows attackers to bypass intended ...

Jan 6, 2026
CVE-2025-69353
5.4

This CVE describes a missing authorization vulnerability in the WordPress Proxy & VPN Blocker plugin that allows attackers to bypass access controls. ...

Jan 6, 2026
CVE-2025-69354
5.4

This CVE describes a Missing Authorization vulnerability in the Better Business Reviews WordPress plugin that allows attackers to exploit incorrectly ...

Jan 6, 2026
CVE-2025-69341
5.4

This CVE describes a Missing Authorization vulnerability in the WeDesignTech Ultimate Booking Addon WordPress plugin that allows attackers to bypass a...

Jan 6, 2026
CVE-2025-69345
5.4

This CVE describes a Missing Authorization vulnerability in BoldGrid Post and Page Builder WordPress plugin that allows attackers to bypass access con...

Jan 6, 2026
CVE-2025-66144
5.4

This CVE describes a Missing Authorization vulnerability in the Worker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...

Dec 31, 2025
CVE-2025-66145
5.4

This CVE describes a Missing Authorization vulnerability in the Worker for WPBakery WordPress plugin that allows attackers to bypass access controls. ...

Dec 31, 2025
CVE-2025-66146
5.4

A missing authorization vulnerability in the Logger for Elementor WordPress plugin allows attackers to bypass access controls and potentially view or ...

Dec 31, 2025
CVE-2025-66148
5.4

This CVE describes a Missing Authorization vulnerability in the Conformer for Elementor WordPress plugin that allows attackers to bypass intended acce...

Dec 31, 2025
CVE-2025-66149
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove UnGrabber WordPress plugin that allows attackers to bypass access controls. ...

Dec 31, 2025
CVE-2025-66150
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Appender WordPress plugin that allows attackers to exploit incorrectly confi...

Dec 31, 2025
CVE-2025-66151
5.4

This CVE describes a missing authorization vulnerability in the Countdowner for Elementor WordPress plugin that allows attackers to bypass access cont...

Dec 31, 2025
CVE-2025-66152
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Criptopayer for Elementor WordPress plugin that allows attackers to exploit ...

Dec 31, 2025
CVE-2025-66153
5.4

This CVE describes a Missing Authorization vulnerability in the Headinger for Elementor WordPress plugin that allows attackers to exploit incorrectly ...

Dec 31, 2025
CVE-2025-66158
5.4

This CVE describes a Missing Authorization vulnerability in the Gmaper for Elementor WordPress plugin that allows attackers to bypass intended access ...

Dec 31, 2025
CVE-2025-66159
5.4

This CVE describes a Missing Authorization vulnerability in the Walker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...

Dec 31, 2025
CVE-2025-66160
5.4

This CVE describes a Missing Authorization vulnerability in the Select Graphist for Elementor WordPress plugin that allows attackers to exploit incorr...

Dec 31, 2025
CVE-2025-66155
5.4

This CVE describes a Missing Authorization vulnerability in the Questionar for Elementor WordPress plugin that allows attackers to bypass intended acc...

Dec 31, 2025
CVE-2025-66156
5.4

CVE-2025-66156 is a missing authorization vulnerability in the Watcher for Elementor WordPress plugin that allows attackers to bypass access controls ...

Dec 31, 2025
CVE-2025-66157
5.4

A missing authorization vulnerability in the merkulove Slider for Elementor WordPress plugin allows attackers to bypass intended access controls. This...

Dec 31, 2025
CVE-2025-66154
5.4

This CVE describes a Missing Authorization vulnerability in the Couponer for Elementor WordPress plugin that allows attackers to exploit incorrectly c...

Dec 31, 2025
CVE-2025-62888
5.4

This CVE describes a Missing Authorization vulnerability in the WP Attachments WordPress plugin that allows attackers to bypass intended access contro...

Dec 31, 2025
CVE-2025-62091
5.4

This CVE describes a Missing Authorization vulnerability in the Vollstart Serial Codes Generator and Validator with WooCommerce Support WordPress plug...

Dec 31, 2025
CVE-2025-62098
5.4

This CVE describes a Missing Authorization vulnerability in the Totalsoft Portfolio Gallery WordPress plugin that allows attackers to bypass access co...

Dec 31, 2025
CVE-2025-62108
5.4

This CVE describes a Missing Authorization vulnerability in the SaifuMak Add Custom Codes WordPress plugin that allows attackers to bypass access cont...

Dec 31, 2025
CVE-2025-62144
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Core Web Vitals & PageSpeed Booster plugin that allows attackers to exploit ...

Dec 31, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free