CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,036
Total CVEs
226
Critical
844
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 34
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,036)

CVE-2025-60103
5.4

This CVE describes a missing authorization vulnerability in the ListingPro WordPress plugin that allows attackers to bypass intended access controls. ...

Sep 26, 2025
CVE-2025-60096
5.4

This vulnerability allows attackers to bypass authorization controls in TheGem (Elementor) WordPress theme, potentially accessing restricted functiona...

Sep 26, 2025
CVE-2025-60097
5.4

This CVE describes a missing authorization vulnerability in the TheGem WordPress theme that allows attackers to bypass access controls. Attackers coul...

Sep 26, 2025
CVE-2025-58672
5.4

This vulnerability allows attackers to bypass authorization controls in WP User Frontend, potentially accessing or modifying content they shouldn't ha...

Sep 22, 2025
CVE-2025-58667
5.4

This CVE describes a missing authorization vulnerability in the WordPress ListingPro Reviews plugin that allows attackers to bypass access controls. I...

Sep 22, 2025
CVE-2025-58660
5.4

This CVE describes a Missing Authorization vulnerability in the Oshine Core WordPress plugin that allows attackers to bypass access controls. Attacker...

Sep 22, 2025
CVE-2025-58650
5.4

This CVE describes a missing authorization vulnerability in the All In One SEO Pack WordPress plugin that allows attackers to exploit incorrectly conf...

Sep 22, 2025
CVE-2025-57990
5.4

This CVE describes a Missing Authorization vulnerability in the Blog Designer WordPress plugin that allows attackers to bypass access controls. It aff...

Sep 22, 2025
CVE-2025-57991
5.4

This CVE describes a missing authorization vulnerability in the Clariti WordPress plugin that allows attackers to bypass access controls. It affects a...

Sep 22, 2025
CVE-2025-57949
5.4

This CVE describes a missing authorization vulnerability in the Ongkoskirim.id WordPress plugin that allows attackers to bypass access controls. It af...

Sep 22, 2025
CVE-2025-8487
5.4

The Kubio AI Page Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or h...

Sep 19, 2025
CVE-2025-8423
5.4

The My WP Translate WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or high...

Sep 11, 2025
CVE-2025-58981
5.4

This CVE describes a Missing Authorization vulnerability in Equalize Digital Accessibility Checker WordPress plugin that allows attackers to bypass ac...

Sep 9, 2025
CVE-2025-53291
5.4

This CVE describes a missing authorization vulnerability in the Spreadconnect WordPress plugin that allows unauthorized users to access functionality ...

Sep 9, 2025
CVE-2025-8712
5.4

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privile...

Sep 9, 2025
CVE-2025-55144
5.4

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privile...

Sep 9, 2025
CVE-2025-42915
5.4

CVE-2025-42915 is an authorization bypass vulnerability in SAP Fiori's Manage Payment Blocks app where insufficient privilege checks allow basic users...

Sep 9, 2025
CVE-2025-53337
5.4

This CVE describes a Missing Authorization vulnerability in the LifePress WordPress plugin that allows attackers to bypass access controls. It affects...

Aug 28, 2025
CVE-2025-54717
5.4

This CVE describes a Missing Authorization vulnerability in the WP Membership WordPress plugin that allows attackers to change plugin settings without...

Aug 14, 2025
CVE-2025-54695
5.4

This CVE describes a Missing Authorization vulnerability in the HasTech HT Mega WordPress plugin that allows attackers to bypass access controls. Atta...

Aug 14, 2025
CVE-2025-8796
5.4

This vulnerability in LitmusChaos Litmus allows unauthorized deletion of projects due to missing authorization checks in the delete project endpoint. ...

Aug 10, 2025
CVE-2025-48167
5.4

This CVE describes a missing authorization vulnerability in the Chatbox Manager WordPress plugin that allows attackers to bypass access controls. Atta...

Jul 16, 2025
CVE-2025-46259
5.4

This CVE describes a missing authorization vulnerability in The Plus Addons for Elementor Pro WordPress plugin. It allows attackers to bypass access c...

Jul 1, 2025
CVE-2025-49998
5.4

This CVE describes a missing authorization vulnerability in the WooCommerce Fortnox Integration plugin for WordPress. Attackers can exploit incorrectl...

Jun 20, 2025
CVE-2025-50009
5.4

This CVE describes a Missing Authorization vulnerability in the Kata Plus WordPress plugin by Climax Themes. It allows attackers to bypass access cont...

Jun 20, 2025
CVE-2025-4571
5.4

The GiveWP WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level permissions or higher to ...

Jun 19, 2025
CVE-2025-30958
5.4

This CVE describes a missing authorization vulnerability in the onOffice for WP-Websites WordPress plugin that allows attackers to bypass intended acc...

Jun 6, 2025
CVE-2025-30636
5.4

This CVE describes a missing authorization vulnerability in Ability, Inc's Accessibility Suite WordPress plugin that allows attackers to bypass intend...

Jun 6, 2025
CVE-2025-29013
5.4

This CVE describes a Missing Authorization vulnerability in the Custom Category/Post Type Post order WordPress plugin that allows attackers to exploit...

Jun 6, 2025
CVE-2025-24776
5.4

This CVE describes a Missing Authorization vulnerability in the Responsive Flipbooks WordPress plugin that allows attackers to bypass access controls....

Jun 6, 2025
CVE-2025-22287
5.4

This CVE describes a Missing Authorization vulnerability in the Eniture Technology LTL Freight Quotes WordPress plugin that allows attackers to exploi...

May 19, 2025
CVE-2025-26920
5.4

This CVE describes a missing authorization vulnerability in the Customify WordPress theme that allows attackers to bypass access controls. It affects ...

May 19, 2025
CVE-2025-48246
5.4

This CVE describes a Missing Authorization vulnerability in The Events Calendar WordPress plugin that allows attackers to exploit incorrectly configur...

May 19, 2025
CVE-2025-47612
5.4

This CVE describes a Missing Authorization vulnerability in the ClickWhale WordPress plugin that allows attackers to exploit incorrectly configured ac...

May 7, 2025
CVE-2025-47602
5.4

This CVE describes a Missing Authorization vulnerability in the Calculate Prices based on Distance For WooCommerce WordPress plugin. It allows attacke...

May 7, 2025
CVE-2025-47480
5.4

This CVE describes a Missing Authorization vulnerability in the Graphina WordPress plugin that allows attackers to bypass access controls. It affects ...

May 7, 2025
CVE-2025-47472
5.4

This CVE describes a Missing Authorization vulnerability in the Music Player for WooCommerce WordPress plugin. It allows attackers to bypass intended ...

May 7, 2025
CVE-2025-39591
5.4

This CVE describes a missing authorization vulnerability in WP Shuffle WP Subscription Forms WordPress plugin that allows attackers to bypass access c...

Apr 16, 2025
CVE-2025-39522
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Dynamic Post plugin that allows unauthorized users to change plugin settings...

Apr 16, 2025
CVE-2025-32246
5.4

This CVE describes a missing authorization vulnerability in the Tim Nguyen 1-Click Backup & Restore Database WordPress plugin. It allows attackers to ...

Apr 4, 2025
CVE-2025-32218
5.4

This CVE describes a missing authorization vulnerability in the TableOn WordPress plugin that allows attackers to bypass intended access controls. Wor...

Apr 4, 2025
CVE-2025-32220
5.4

A missing authorization vulnerability in the Dimitri Grassi Salon booking system WordPress plugin allows attackers to bypass access controls and perfo...

Apr 4, 2025
CVE-2025-31794
5.4

This CVE describes a Missing Authorization vulnerability in the WR Price List Manager For Woocommerce WordPress plugin that allows attackers to delete...

Apr 3, 2025
CVE-2025-31878
5.4

This CVE describes a Missing Authorization vulnerability in the UPC/EAN/GTIN Code Generator WordPress plugin that allows unauthorized users to change ...

Apr 1, 2025
CVE-2025-31826
5.4

This CVE describes a Missing Authorization vulnerability in the Ni WooCommerce Cost Of Goods plugin for WordPress. It allows attackers to exploit inco...

Apr 1, 2025
CVE-2025-31816
5.4

This CVE describes a missing authorization vulnerability in the Mobile App Canvas WordPress plugin that allows attackers to bypass access controls. It...

Apr 1, 2025
CVE-2025-31802
5.4

A missing authorization vulnerability in Shiptimize for WooCommerce allows attackers to change plugin settings without proper authentication. This aff...

Apr 1, 2025
CVE-2025-31791
5.4

This CVE describes a missing authorization vulnerability in the Pin Generator WordPress plugin that allows attackers to bypass access controls. Attack...

Apr 1, 2025
CVE-2025-31782
5.4

This CVE describes a missing authorization vulnerability in the mb.YTPlayer WordPress plugin that allows attackers to bypass access controls. Attacker...

Apr 1, 2025
CVE-2025-31584
5.4

This CVE describes a Missing Authorization vulnerability in the Elfsight Testimonials Slider WordPress plugin that allows attackers to bypass access c...

Mar 31, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,036 CVEs classified as CWE-862, with 226 rated critical and 844 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free