CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,038
Total CVEs
226
Critical
846
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 17
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,038)

CVE-2025-31782
5.4

This CVE describes a missing authorization vulnerability in the mb.YTPlayer WordPress plugin that allows attackers to bypass access controls. Attacker...

Apr 1, 2025
CVE-2025-31584
5.4

This CVE describes a Missing Authorization vulnerability in the Elfsight Testimonials Slider WordPress plugin that allows attackers to bypass access c...

Mar 31, 2025
CVE-2025-31545
5.4

This CVE describes a Missing Authorization vulnerability in the WP Messiah Safe Ai Malware Protection for WordPress plugin. It allows attackers to exp...

Mar 31, 2025
CVE-2025-22770
5.4

This CVE describes a missing authorization vulnerability in the Envo Multipurpose WordPress theme that allows attackers to bypass access controls. It ...

Mar 27, 2025
CVE-2025-30896
5.4

This CVE describes a Missing Authorization vulnerability in weDevs WP ERP WordPress plugin that allows attackers to bypass access controls. It affects...

Mar 27, 2025
CVE-2025-30817
5.4

This CVE describes a missing authorization vulnerability in the wpzita Z Companion WordPress plugin that allows attackers to bypass access controls. I...

Mar 27, 2025
CVE-2025-30809
5.4

A missing authorization vulnerability in the Shahjada Live Forms WordPress plugin allows attackers to change plugin settings without proper authentica...

Mar 27, 2025
CVE-2025-1681
5.4

The Cardealer WordPress theme has a vulnerability that allows authenticated users with subscriber-level access or higher to modify or delete arbitrary...

Feb 28, 2025
CVE-2025-26995
5.4

CVE-2025-26995 is a missing authorization vulnerability in the Market Exporter WordPress plugin that allows attackers to bypass access controls and po...

Feb 25, 2025
CVE-2025-27356
5.4

This CVE describes a missing authorization vulnerability in the WordPress Sticky Header On Scroll plugin that allows attackers to bypass access contro...

Feb 24, 2025
CVE-2025-25241
5.4

CVE-2025-25241 is a missing authorization vulnerability in SAP applications that allows authenticated attackers to view and delete other users' overti...

Feb 11, 2025
CVE-2025-25110
5.4

This CVE describes a missing authorization vulnerability in the Metagauss Event Kikfyre WordPress plugin that allows attackers to bypass access contro...

Feb 7, 2025
CVE-2025-22696
5.4

This CVE describes a missing authorization vulnerability in the WordPress EmbedPress Document Block plugin that allows unauthorized users to perform a...

Feb 4, 2025
CVE-2024-13775
5.4

The WooCommerce Support Ticket System plugin for WordPress has missing capability checks on three AJAX functions, allowing authenticated attackers wit...

Feb 1, 2025
CVE-2024-12825
5.4

The Custom Related Posts WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or...

Feb 1, 2025
CVE-2025-23849
5.4

CVE-2025-23849 is a missing authorization vulnerability in the PAPERCITE WordPress plugin that allows attackers to bypass access controls and perform ...

Jan 27, 2025
CVE-2025-24604
5.4

This CVE describes a missing authorization vulnerability in the VForm WordPress plugin that allows attackers to bypass access controls. It affects all...

Jan 24, 2025
CVE-2025-24571
5.4

This CVE describes a missing authorization vulnerability in the WP Fast Total Search WordPress plugin that allows attackers to bypass access controls....

Jan 24, 2025
CVE-2025-23916
5.4

This CVE describes a Missing Authorization vulnerability in the WP Meetup WordPress plugin that allows attackers to change plugin settings without pro...

Jan 16, 2025
CVE-2025-23761
5.4

This CVE describes a missing authorization vulnerability in the Woo Tuner WordPress plugin that allows attackers to exploit incorrectly configured acc...

Jan 16, 2025
CVE-2025-22534
5.4

This CVE describes a missing authorization vulnerability in the Ella van Durpe Slides & Presentations WordPress plugin that allows attackers to bypass...

Jan 7, 2025
CVE-2025-22541
5.4

This CVE describes a Missing Authorization vulnerability in the WP Delete Post Copies WordPress plugin that allows attackers to exploit incorrectly co...

Jan 7, 2025
CVE-2023-23672
5.4

CVE-2023-23672 is a missing authorization vulnerability in the GiveWP WordPress plugin that allows authenticated users to delete arbitrary content wit...

Jan 2, 2025
CVE-2022-45811
5.4

CVE-2022-45811 is a missing authorization vulnerability in the WordPress Post Teaser plugin that allows attackers to perform unauthorized actions. Thi...

Jan 2, 2025
CVE-2023-32240
5.4

This CVE describes a missing authorization vulnerability in the Xtemos WoodMart WordPress theme that allows attackers to bypass access controls. Attac...

Jan 2, 2025
CVE-2024-56253
5.4

This CVE describes a Missing Authorization vulnerability in the Data Tables Generator by Supsystic WordPress plugin. It allows attackers to exploit in...

Jan 2, 2025
CVE-2024-56244
5.4

This CVE describes a Missing Authorization vulnerability in the WP Royal Ashe Extra WordPress plugin that allows attackers to exploit incorrectly conf...

Jan 2, 2025
CVE-2023-47661
5.4

This CVE describes a Missing Authorization vulnerability in Dragfy Addons for Elementor WordPress plugin that allows attackers to exploit incorrectly ...

Jan 2, 2025
CVE-2023-47187
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Animated Rotating Words plugin that allows attackers to exploit incorrectly ...

Jan 2, 2025
CVE-2023-47225
5.4

This CVE describes a Missing Authorization vulnerability in the KaizenCoders Short URL WordPress plugin that allows attackers to exploit incorrectly c...

Jan 2, 2025
CVE-2023-46633
5.4

This CVE describes a missing authorization vulnerability in the TCBarrett Glossary WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 2, 2025
CVE-2023-45636
5.4

This CVE describes a missing authorization vulnerability in the WebToffee WordPress Backup & Migration plugin that allows attackers to bypass access c...

Jan 2, 2025
CVE-2024-49686
5.4

CVE-2024-49686 is a missing authorization vulnerability in the Landing Page Cat WordPress plugin that allows attackers to perform unauthorized actions...

Dec 31, 2024
CVE-2024-56225
5.4

This CVE describes a Missing Authorization vulnerability in the Premium Addons for Elementor WordPress plugin. It allows attackers to access functiona...

Dec 31, 2024
CVE-2024-12617
5.4

The WC Price History for Omnibus WordPress plugin has missing capability checks on AJAX actions, allowing authenticated users with Subscriber-level ac...

Dec 24, 2024
CVE-2024-54311
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Mark New Posts plugin that allows attackers to bypass access controls. It af...

Dec 13, 2024
CVE-2023-44142
5.4

This CVE describes a missing authorization vulnerability in the Inactive Logout WordPress plugin that allows attackers to bypass access controls. It a...

Dec 13, 2024
CVE-2023-41857
5.4

This CVE describes a Missing Authorization vulnerability in the Click To Tweet WordPress plugin that allows attackers to exploit incorrectly configure...

Dec 13, 2024
CVE-2023-41683
5.4

This CVE describes a missing authorization vulnerability in the Pechenki TelSender WordPress plugin that allows attackers to bypass access controls. A...

Dec 13, 2024
CVE-2023-41688
5.4

This CVE describes a Missing Authorization vulnerability in the Bulk NoIndex & NoFollow Toolkit WordPress plugin. It allows attackers to exploit incor...

Dec 13, 2024
CVE-2023-37989
5.4

This CVE describes a missing authorization vulnerability in the Easyship WooCommerce Shipping Rates plugin that allows attackers to exploit incorrectl...

Dec 13, 2024
CVE-2023-36519
5.4

CVE-2023-36519 is a missing authorization vulnerability in the SW Product Bundles WordPress plugin that allows attackers to bypass access controls and...

Dec 13, 2024
CVE-2023-36680
5.4

This CVE describes a missing authorization vulnerability in the WordPress Image Regenerate & Select Crop plugin that allows attackers to exploit incor...

Dec 13, 2024
CVE-2023-35051
5.4

This CVE describes a missing authorization vulnerability in the Contact Forms by Cimatti WordPress plugin that allows attackers to bypass access contr...

Dec 13, 2024
CVE-2023-32601
5.4

This CVE describes a Missing Authorization vulnerability in the Booking Ultra Pro WordPress plugin that allows attackers to bypass access controls. It...

Dec 13, 2024
CVE-2023-32581
5.4

This CVE describes a Missing Authorization vulnerability in the MobileMonkey WP-Chatbot for Messenger WordPress plugin. It allows attackers to bypass ...

Dec 13, 2024
CVE-2023-32593
5.4

This CVE describes a Missing Authorization vulnerability in the GS Pins for Pinterest WordPress plugin that allows attackers to bypass access controls...

Dec 13, 2024
CVE-2022-45826
5.4

This CVE describes a missing authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to exploit incorrectly conf...

Dec 13, 2024
CVE-2022-45841
5.4

This CVE describes a missing authorization vulnerability in the Robo Gallery WordPress plugin that allows attackers to exploit incorrectly configured ...

Dec 13, 2024
CVE-2024-55876
5.4

This vulnerability allows any authenticated user on the main XWiki wiki to execute scheduling operations on subwikis without proper authorization. It ...

Dec 12, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,038 CVEs classified as CWE-862, with 226 rated critical and 846 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free