CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,036
Total CVEs
226
Critical
844
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,036)

CVE-2025-69027
5.4

This CVE describes a Missing Authorization vulnerability in the Product Delivery Date for WooCommerce – Lite WordPress plugin that allows attackers ...

Dec 30, 2025
CVE-2025-69022
5.4

This CVE describes a missing authorization vulnerability in the HR Management Lite WordPress plugin that allows attackers to bypass access controls. I...

Dec 30, 2025
CVE-2023-41656
5.4

This CVE describes a Missing Authorization vulnerability in the Better Elementor Addons WordPress plugin that allows attackers to bypass access contro...

Dec 30, 2025
CVE-2023-25445
5.4

This CVE describes a Missing Authorization vulnerability in HappyFiles Pro WordPress plugin that allows attackers to bypass access controls. It affect...

Dec 21, 2025
CVE-2025-14455
5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to bypass authorization checks in the Image Photo Gall...

Dec 19, 2025
CVE-2025-62960
5.4

This CVE describes a missing authorization vulnerability in the Sparkle WP Construction Light WordPress theme that allows attackers to bypass intended...

Dec 18, 2025
CVE-2025-62961
5.4

This CVE describes a missing authorization vulnerability in the Sparkle FSE WordPress theme that allows attackers to bypass access controls. It affect...

Dec 18, 2025
CVE-2025-68088
5.4

This CVE describes a Missing Authorization vulnerability in the Huger for Elementor WordPress plugin that allows attackers to bypass access controls. ...

Dec 16, 2025
CVE-2025-68084
5.4

This CVE describes a Missing Authorization vulnerability in the Ultimate Auction WordPress plugin that allows attackers to bypass access controls. It ...

Dec 16, 2025
CVE-2025-68085
5.4

This CVE describes a Missing Authorization vulnerability in the Buttoner for Elementor WordPress plugin that allows attackers to change plugin setting...

Dec 16, 2025
CVE-2025-68086
5.4

This CVE describes a Missing Authorization vulnerability in the Reformer for Elementor WordPress plugin that allows attackers to exploit incorrectly c...

Dec 16, 2025
CVE-2025-68087
5.4

This CVE describes a missing authorization vulnerability in the Modalier for Elementor WordPress plugin that allows attackers to bypass access control...

Dec 16, 2025
CVE-2025-66167
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Lottier WordPress plugin that allows attackers to bypass access controls. It...

Dec 16, 2025
CVE-2025-66134
5.4

This CVE describes a Missing Authorization vulnerability in the FileBird Pro WordPress plugin that allows attackers to bypass access controls. Attacke...

Dec 16, 2025
CVE-2025-66147
5.4

This CVE describes a Missing Authorization vulnerability in the merkulove Coder for Elementor WordPress plugin that allows attackers to exploit incorr...

Dec 16, 2025
CVE-2025-66161
5.4

This CVE describes a missing authorization vulnerability in the Grider for Elementor WordPress plugin that allows attackers to bypass intended access ...

Dec 16, 2025
CVE-2025-66162
5.4

This CVE describes a Missing Authorization vulnerability in the Spoter for Elementor WordPress plugin that allows attackers to exploit incorrectly con...

Dec 16, 2025
CVE-2025-66163
5.4

This CVE describes a Missing Authorization vulnerability in the Masker for Elementor WordPress plugin that allows attackers to exploit incorrectly con...

Dec 16, 2025
CVE-2025-66164
5.4

This CVE describes a Missing Authorization vulnerability in the Laser WordPress plugin that allows attackers to bypass access controls. It affects all...

Dec 16, 2025
CVE-2025-66165
5.4

This CVE describes a Missing Authorization vulnerability in the Lottier for WPBakery WordPress plugin that allows attackers to exploit incorrectly con...

Dec 16, 2025
CVE-2025-66166
5.4

This CVE describes a Missing Authorization vulnerability in the Lottier for Elementor WordPress plugin that allows attackers to bypass intended access...

Dec 16, 2025
CVE-2025-66127
5.4

This CVE describes a missing authorization vulnerability in the Essential Real Estate WordPress plugin that allows attackers to bypass access controls...

Dec 16, 2025
CVE-2025-66122
5.4

This CVE describes a missing authorization vulnerability in the Stylish Price List WordPress plugin that allows attackers to exploit incorrectly confi...

Dec 16, 2025
CVE-2025-64635
5.4

This CVE describes a missing authorization vulnerability in the Feeds for YouTube WordPress plugin that allows attackers to bypass access controls. It...

Dec 16, 2025
CVE-2023-23729
5.4

This vulnerability allows users with Contributor-level access in WordPress to modify reCAPTCHA settings in the Spectra plugin, which should be restric...

Dec 9, 2025
CVE-2025-67559
5.4

This CVE describes a Missing Authorization vulnerability in the vcita Online Booking & Scheduling Calendar WordPress plugin that allows attackers to e...

Dec 9, 2025
CVE-2025-67561
5.4

This CVE describes a missing authorization vulnerability in the Debug Log Viewer WordPress plugin that allows unauthorized users to access debug logs....

Dec 9, 2025
CVE-2025-63034
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Page View Count plugin that allows unauthorized users to change plugin setti...

Dec 9, 2025
CVE-2025-63024
5.4

This vulnerability allows unauthorized users to access functionality intended only for authenticated users in the Order Delivery Date for WooCommerce ...

Dec 9, 2025
CVE-2025-62999
5.4

This CVE describes a missing authorization vulnerability in the Litho Addons WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 9, 2025
CVE-2025-62086
5.4

This CVE describes a Missing Authorization vulnerability in the Яндекс Доставка (Boxberry) WordPress plugin that allows attackers to exp...

Dec 9, 2025
CVE-2025-12887
5.4

The Post SMTP WordPress plugin has an authorization bypass vulnerability that allows authenticated attackers with subscriber-level access or higher to...

Dec 3, 2025
CVE-2025-13558
5.4

This vulnerability in the Blog2Social WordPress plugin allows authenticated users with Subscriber-level access or higher to trash arbitrary posts with...

Nov 25, 2025
CVE-2025-66113
5.4

This CVE describes a Missing Authorization vulnerability in the Better Chat Support for Messenger WordPress plugin that allows attackers to bypass acc...

Nov 21, 2025
CVE-2025-66063
5.4

This CVE describes a Missing Authorization vulnerability in the WP Google Review Slider WordPress plugin that allows attackers to exploit incorrectly ...

Nov 21, 2025
CVE-2025-62293
5.4

SOPlanning versions before 1.55 have a broken access control vulnerability in the /status endpoint that allows authenticated attackers to manipulate p...

Nov 20, 2025
CVE-2025-13468
5.4

This vulnerability allows unauthorized deletion of forum posts, careers, comments, gallery items, and events in SourceCodester Alumni Management Syste...

Nov 20, 2025
CVE-2025-11734
5.4

This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to delete arbitrary posts without proper authoriz...

Nov 18, 2025
CVE-2025-64263
5.4

This CVE describes a Missing Authorization vulnerability in the WP Content Pilot WordPress plugin that allows attackers to exploit incorrectly configu...

Nov 13, 2025
CVE-2025-64150
5.4

This vulnerability in Jenkins Publish to Bitbucket Plugin allows attackers with Overall/Read permission to connect to attacker-controlled URLs using s...

Oct 29, 2025
CVE-2025-64132
5.4

The Jenkins MCP Server Plugin vulnerability allows attackers to bypass permission checks and trigger unauthorized builds or access sensitive job/cloud...

Oct 29, 2025
CVE-2025-64212
5.4

This CVE describes a missing authorization vulnerability in the MasterStudy LMS Pro WordPress plugin that allows attackers to bypass access controls a...

Oct 29, 2025
CVE-2025-64210
5.4

This CVE describes a missing authorization vulnerability in the Masterstudy Elementor Widgets WordPress plugin that allows attackers to exploit incorr...

Oct 29, 2025
CVE-2025-10749
5.4

The Microsoft Azure Storage for WordPress plugin has a vulnerability that allows authenticated users with subscriber-level access or higher to delete ...

Oct 24, 2025
CVE-2025-62027
5.4

This CVE describes a Missing Authorization vulnerability in the StellarWP Event Tickets WordPress plugin that allows unauthorized users to perform act...

Oct 22, 2025
CVE-2025-62048
5.4

This CVE describes a missing authorization vulnerability in the SmartCrawl SEO WordPress plugin that allows authenticated users to perform actions the...

Oct 22, 2025
CVE-2025-49920
5.4

This CVE describes a missing authorization vulnerability in the accessiBe WordPress plugin that allows attackers to bypass access controls. It affects...

Oct 22, 2025
CVE-2025-11378
5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to export and import site options without proper autho...

Oct 18, 2025
CVE-2025-41410
5.4

This vulnerability allows attackers to create verified user accounts with arbitrary email domains during Slack imports in Mattermost. Attackers can by...

Oct 16, 2025
CVE-2025-60116
5.4

This CVE describes a missing authorization vulnerability in the Grand Conference Theme Custom Post Type WordPress plugin that allows attackers to bypa...

Sep 26, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free