CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,036)
This CVE describes a Missing Authorization vulnerability in the Product Delivery Date for WooCommerce – Lite WordPress plugin that allows attackers ...
Dec 30, 2025This CVE describes a missing authorization vulnerability in the HR Management Lite WordPress plugin that allows attackers to bypass access controls. I...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Better Elementor Addons WordPress plugin that allows attackers to bypass access contro...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in HappyFiles Pro WordPress plugin that allows attackers to bypass access controls. It affect...
Dec 21, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to bypass authorization checks in the Image Photo Gall...
Dec 19, 2025This CVE describes a missing authorization vulnerability in the Sparkle WP Construction Light WordPress theme that allows attackers to bypass intended...
Dec 18, 2025This CVE describes a missing authorization vulnerability in the Sparkle FSE WordPress theme that allows attackers to bypass access controls. It affect...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Huger for Elementor WordPress plugin that allows attackers to bypass access controls. ...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Ultimate Auction WordPress plugin that allows attackers to bypass access controls. It ...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Buttoner for Elementor WordPress plugin that allows attackers to change plugin setting...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Reformer for Elementor WordPress plugin that allows attackers to exploit incorrectly c...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Modalier for Elementor WordPress plugin that allows attackers to bypass access control...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the merkulove Lottier WordPress plugin that allows attackers to bypass access controls. It...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the FileBird Pro WordPress plugin that allows attackers to bypass access controls. Attacke...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the merkulove Coder for Elementor WordPress plugin that allows attackers to exploit incorr...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Grider for Elementor WordPress plugin that allows attackers to bypass intended access ...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Spoter for Elementor WordPress plugin that allows attackers to exploit incorrectly con...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Masker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Laser WordPress plugin that allows attackers to bypass access controls. It affects all...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Lottier for WPBakery WordPress plugin that allows attackers to exploit incorrectly con...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Lottier for Elementor WordPress plugin that allows attackers to bypass intended access...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Essential Real Estate WordPress plugin that allows attackers to bypass access controls...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Stylish Price List WordPress plugin that allows attackers to exploit incorrectly confi...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Feeds for YouTube WordPress plugin that allows attackers to bypass access controls. It...
Dec 16, 2025This vulnerability allows users with Contributor-level access in WordPress to modify reCAPTCHA settings in the Spectra plugin, which should be restric...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the vcita Online Booking & Scheduling Calendar WordPress plugin that allows attackers to e...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Debug Log Viewer WordPress plugin that allows unauthorized users to access debug logs....
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Page View Count plugin that allows unauthorized users to change plugin setti...
Dec 9, 2025This vulnerability allows unauthorized users to access functionality intended only for authenticated users in the Order Delivery Date for WooCommerce ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Litho Addons WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Яндекс Доставка (Boxberry) WordPress plugin that allows attackers to exp...
Dec 9, 2025The Post SMTP WordPress plugin has an authorization bypass vulnerability that allows authenticated attackers with subscriber-level access or higher to...
Dec 3, 2025This vulnerability in the Blog2Social WordPress plugin allows authenticated users with Subscriber-level access or higher to trash arbitrary posts with...
Nov 25, 2025This CVE describes a Missing Authorization vulnerability in the Better Chat Support for Messenger WordPress plugin that allows attackers to bypass acc...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the WP Google Review Slider WordPress plugin that allows attackers to exploit incorrectly ...
Nov 21, 2025SOPlanning versions before 1.55 have a broken access control vulnerability in the /status endpoint that allows authenticated attackers to manipulate p...
Nov 20, 2025This vulnerability allows unauthorized deletion of forum posts, careers, comments, gallery items, and events in SourceCodester Alumni Management Syste...
Nov 20, 2025This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to delete arbitrary posts without proper authoriz...
Nov 18, 2025This CVE describes a Missing Authorization vulnerability in the WP Content Pilot WordPress plugin that allows attackers to exploit incorrectly configu...
Nov 13, 2025This vulnerability in Jenkins Publish to Bitbucket Plugin allows attackers with Overall/Read permission to connect to attacker-controlled URLs using s...
Oct 29, 2025The Jenkins MCP Server Plugin vulnerability allows attackers to bypass permission checks and trigger unauthorized builds or access sensitive job/cloud...
Oct 29, 2025This CVE describes a missing authorization vulnerability in the MasterStudy LMS Pro WordPress plugin that allows attackers to bypass access controls a...
Oct 29, 2025This CVE describes a missing authorization vulnerability in the Masterstudy Elementor Widgets WordPress plugin that allows attackers to exploit incorr...
Oct 29, 2025The Microsoft Azure Storage for WordPress plugin has a vulnerability that allows authenticated users with subscriber-level access or higher to delete ...
Oct 24, 2025This CVE describes a Missing Authorization vulnerability in the StellarWP Event Tickets WordPress plugin that allows unauthorized users to perform act...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the SmartCrawl SEO WordPress plugin that allows authenticated users to perform actions the...
Oct 22, 2025This CVE describes a missing authorization vulnerability in the accessiBe WordPress plugin that allows attackers to bypass access controls. It affects...
Oct 22, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to export and import site options without proper autho...
Oct 18, 2025This vulnerability allows attackers to create verified user accounts with arbitrary email domains during Slack imports in Mattermost. Attackers can by...
Oct 16, 2025This CVE describes a missing authorization vulnerability in the Grand Conference Theme Custom Post Type WordPress plugin that allows attackers to bypa...
Sep 26, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free