CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,038
Total CVEs
226
Critical
846
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 17
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,038)

CVE-2024-54217
5.4

This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows authenticated users with subscriber-level permiss...

Dec 9, 2024
CVE-2024-53798
5.4

This CVE describes a Missing Authorization vulnerability in the FloristPress WordPress plugin, allowing unauthorized users to perform actions intended...

Dec 9, 2024
CVE-2023-50899
5.4

This CVE describes a Missing Authorization vulnerability in MultiVendorX's Product Catalog Enquiry for WooCommerce plugin. It allows attackers to expl...

Dec 9, 2024
CVE-2023-51359
5.4

This CVE describes a missing authorization vulnerability in the Essential Blocks for Gutenberg WordPress plugin that allows users with lower privilege...

Dec 9, 2024
CVE-2023-49756
5.4

This CVE describes a Missing Authorization vulnerability in the Themewinter Eventin WordPress plugin that allows authenticated users to exploit incorr...

Dec 9, 2024
CVE-2023-48324
5.4

This CVE describes a missing authorization vulnerability in the Awesome Support WordPress plugin that allows attackers to bypass access controls and p...

Dec 9, 2024
CVE-2023-48774
5.4

This CVE describes a Missing Authorization vulnerability in the IdeaPush WordPress plugin that allows attackers to exploit incorrectly configured acce...

Dec 9, 2024
CVE-2023-47822
5.4

This CVE describes a Missing Authorization vulnerability in the Sonaar Music MP3 Audio Player WordPress plugin that allows attackers to exploit incorr...

Dec 9, 2024
CVE-2023-30873
5.4

This CVE describes a Missing Authorization vulnerability in the WP Docs WordPress plugin that allows attackers to bypass access controls and access re...

Dec 9, 2024
CVE-2023-31214
5.4

This CVE describes a Missing Authorization vulnerability in the WP Quick Post Duplicator WordPress plugin that allows attackers to exploit incorrectly...

Dec 9, 2024
CVE-2023-29433
5.4

This CVE describes a Missing Authorization vulnerability in the Tencent Cloud COS WordPress plugin that allows attackers to exploit incorrectly config...

Dec 9, 2024
CVE-2023-29239
5.4

This CVE describes a Missing Authorization vulnerability in the LuckyWP Scripts Control WordPress plugin that allows attackers to exploit incorrectly ...

Dec 9, 2024
CVE-2023-25959
5.4

This CVE describes a Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions WordPress plugin that allows attackers to byp...

Dec 9, 2024
CVE-2023-23886
5.4

This vulnerability allows attackers to bypass authorization controls in the WP-RecentComments WordPress plugin, potentially accessing restricted funct...

Dec 9, 2024
CVE-2024-53806
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Maspik plugin that allows attackers to change plugin settings via Cross-Site...

Dec 6, 2024
CVE-2024-10665
5.4

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view and delete payment gateway logs without proper ...

Nov 20, 2024
CVE-2024-51817
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Combo WP Rewrite Slugs plugin that allows attackers to change plugin setting...

Nov 19, 2024
CVE-2024-11085
5.4

The WP Log Viewer WordPress plugin has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or highe...

Nov 16, 2024
CVE-2024-43962
5.4

This CVE describes a Missing Authorization vulnerability in the LWS Affiliation WordPress plugin that allows attackers to bypass access controls. It a...

Nov 1, 2024
CVE-2024-43268
5.4

This CVE describes a broken access control vulnerability in the WPBackItUp Backup and Restore WordPress plugin. It allows unauthorized users to perfor...

Nov 1, 2024
CVE-2024-43273
5.4

This CVE describes a Missing Authorization vulnerability in the Icegram Collect WordPress plugin that allows attackers to exploit incorrectly configur...

Nov 1, 2024
CVE-2024-38737
5.4

This CVE describes a Missing Authorization vulnerability in the ReDi Restaurant Reservation WordPress plugin that allows attackers to access functiona...

Nov 1, 2024
CVE-2024-37415
5.4

This CVE describes a Missing Authorization vulnerability in the E2Pdf WordPress plugin that allows attackers to bypass access controls. It affects all...

Nov 1, 2024
CVE-2024-37250
5.4

This vulnerability allows attackers with subscriber-level access to perform unauthorized actions in Advanced Custom Fields PRO for WordPress. It affec...

Nov 1, 2024
CVE-2024-50456
5.4

This CVE describes a Missing Authorization vulnerability in the SEOPress WordPress plugin that allows attackers to exploit incorrectly configured acce...

Oct 29, 2024
CVE-2024-9630
5.4

The WPS Telegram Chat WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view messages sent through t...

Oct 25, 2024
CVE-2023-7289
5.4

This vulnerability allows authenticated WordPress users with subscriber-level permissions to change the Paytium plugin's API keys without authorizatio...

Oct 16, 2024
CVE-2023-7287
5.4

This vulnerability allows authenticated WordPress users with subscriber-level permissions to cancel subscriptions managed by the Paytium plugin. It af...

Oct 16, 2024
CVE-2024-20477
5.4

This vulnerability allows authenticated low-privileged attackers to upload or delete files on Cisco NDFC devices via a specific REST API endpoint with...

Oct 2, 2024
CVE-2024-45285
5.4

This CVE-2024-45285 vulnerability in SAP's RFC-enabled function module allows low-privileged authenticated users to perform denial-of-service attacks ...

Sep 10, 2024
CVE-2024-44117
5.4

This CVE allows low-privileged users in SAP systems to modify other users' favorite node URLs and workbook IDs through an RFC-enabled function module....

Sep 10, 2024
CVE-2024-42371
5.4

This CVE allows low-privileged users to delete workplace favorites of any user in SAP systems, potentially exposing usernames and workplace/node infor...

Sep 10, 2024
CVE-2024-5987
5.4

The WP Accessibility Helper WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher...

Aug 29, 2024
CVE-2024-6392
5.4

The Sirv WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher to modif...

Jul 11, 2024
CVE-2024-37542
5.4

This CVE describes a Missing Authorization vulnerability in the WpDevArt Responsive Image Gallery, Gallery Album WordPress plugin. It allows unauthori...

Jul 6, 2024
CVE-2024-36995
5.4

This CVE allows low-privileged users without admin or power roles to create experimental items in Splunk Enterprise and Splunk Cloud Platform. This vi...

Jul 1, 2024
CVE-2023-36676
5.4

This CVE describes a Missing Authorization vulnerability in the Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) that allows unauthor...

Jun 19, 2024
CVE-2023-44151
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Pre-Publish Checklist plugin by Brainstorm Force. It allows unauthorized use...

Jun 19, 2024
CVE-2023-51497
5.4

This CVE describes a Missing Authorization vulnerability in the WooCommerce Ship to Multiple Addresses plugin for WordPress. It allows unauthorized us...

Jun 14, 2024
CVE-2023-51516
5.4

This CVE describes a Missing Authorization vulnerability in the Business Directory Plugin for WordPress. It allows unauthorized users to perform actio...

Jun 14, 2024
CVE-2023-38395
5.4

CVE-2023-38395 is a missing authorization vulnerability in the WP Clone Menu WordPress plugin that allows unauthorized users to perform administrative...

Jun 12, 2024
CVE-2023-51679
5.4

This vulnerability allows unauthorized users to access administrative functions in the BulkGate SMS Plugin for WooCommerce due to missing authorizatio...

Jun 12, 2024
CVE-2024-34815
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress 'Import and export users and customers' plugin. It allows unauthorized users...

Jun 11, 2024
CVE-2024-35662
5.4

This CVE describes a Missing Authorization vulnerability in the Simple COD Fees for WooCommerce WordPress plugin. It allows unauthorized users to perf...

Jun 9, 2024
CVE-2024-32824
5.4

This CVE describes a Missing Authorization vulnerability in the WordPress Evergreen Content Poster plugin that allows unauthorized users to perform ac...

Jun 9, 2024
CVE-2024-30464
5.4

This CVE describes a Missing Authorization vulnerability in the WPZOOM Social Icons Widget & Block WordPress plugin. It allows attackers to perform un...

Jun 9, 2024
CVE-2024-30466
5.4

This CVE describes a Missing Authorization vulnerability in OnTheGoSystems' WooCommerce Multilingual & Multicurrency WordPress plugin. It allows unaut...

Jun 9, 2024
CVE-2024-24716
5.4

This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...

Jun 9, 2024
CVE-2023-23640
5.4

This CVE describes a Missing Authorization vulnerability in the MainWP UpdraftPlus Extension for WordPress. It allows users with Subscriber-level perm...

Jun 9, 2024
CVE-2023-6876
5.4

This vulnerability in the Clever Fox WordPress plugin allows authenticated users with subscriber-level access or higher to change the active theme wit...

Jun 7, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,038 CVEs classified as CWE-862, with 226 rated critical and 846 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free