CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,038)
This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows authenticated users with subscriber-level permiss...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the FloristPress WordPress plugin, allowing unauthorized users to perform actions intended...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in MultiVendorX's Product Catalog Enquiry for WooCommerce plugin. It allows attackers to expl...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Essential Blocks for Gutenberg WordPress plugin that allows users with lower privilege...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Themewinter Eventin WordPress plugin that allows authenticated users to exploit incorr...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Awesome Support WordPress plugin that allows attackers to bypass access controls and p...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the IdeaPush WordPress plugin that allows attackers to exploit incorrectly configured acce...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Sonaar Music MP3 Audio Player WordPress plugin that allows attackers to exploit incorr...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the WP Docs WordPress plugin that allows attackers to bypass access controls and access re...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the WP Quick Post Duplicator WordPress plugin that allows attackers to exploit incorrectly...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Tencent Cloud COS WordPress plugin that allows attackers to exploit incorrectly config...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the LuckyWP Scripts Control WordPress plugin that allows attackers to exploit incorrectly ...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions WordPress plugin that allows attackers to byp...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the WP-RecentComments WordPress plugin, potentially accessing restricted funct...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Maspik plugin that allows attackers to change plugin settings via Cross-Site...
Dec 6, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view and delete payment gateway logs without proper ...
Nov 20, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Combo WP Rewrite Slugs plugin that allows attackers to change plugin setting...
Nov 19, 2024The WP Log Viewer WordPress plugin has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or highe...
Nov 16, 2024This CVE describes a Missing Authorization vulnerability in the LWS Affiliation WordPress plugin that allows attackers to bypass access controls. It a...
Nov 1, 2024This CVE describes a broken access control vulnerability in the WPBackItUp Backup and Restore WordPress plugin. It allows unauthorized users to perfor...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Icegram Collect WordPress plugin that allows attackers to exploit incorrectly configur...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the ReDi Restaurant Reservation WordPress plugin that allows attackers to access functiona...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the E2Pdf WordPress plugin that allows attackers to bypass access controls. It affects all...
Nov 1, 2024This vulnerability allows attackers with subscriber-level access to perform unauthorized actions in Advanced Custom Fields PRO for WordPress. It affec...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the SEOPress WordPress plugin that allows attackers to exploit incorrectly configured acce...
Oct 29, 2024The WPS Telegram Chat WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view messages sent through t...
Oct 25, 2024This vulnerability allows authenticated WordPress users with subscriber-level permissions to change the Paytium plugin's API keys without authorizatio...
Oct 16, 2024This vulnerability allows authenticated WordPress users with subscriber-level permissions to cancel subscriptions managed by the Paytium plugin. It af...
Oct 16, 2024This vulnerability allows authenticated low-privileged attackers to upload or delete files on Cisco NDFC devices via a specific REST API endpoint with...
Oct 2, 2024This CVE-2024-45285 vulnerability in SAP's RFC-enabled function module allows low-privileged authenticated users to perform denial-of-service attacks ...
Sep 10, 2024This CVE allows low-privileged users in SAP systems to modify other users' favorite node URLs and workbook IDs through an RFC-enabled function module....
Sep 10, 2024This CVE allows low-privileged users to delete workplace favorites of any user in SAP systems, potentially exposing usernames and workplace/node infor...
Sep 10, 2024The WP Accessibility Helper WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher...
Aug 29, 2024The Sirv WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher to modif...
Jul 11, 2024This CVE describes a Missing Authorization vulnerability in the WpDevArt Responsive Image Gallery, Gallery Album WordPress plugin. It allows unauthori...
Jul 6, 2024This CVE allows low-privileged users without admin or power roles to create experimental items in Splunk Enterprise and Splunk Cloud Platform. This vi...
Jul 1, 2024This CVE describes a Missing Authorization vulnerability in the Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) that allows unauthor...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Pre-Publish Checklist plugin by Brainstorm Force. It allows unauthorized use...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the WooCommerce Ship to Multiple Addresses plugin for WordPress. It allows unauthorized us...
Jun 14, 2024This CVE describes a Missing Authorization vulnerability in the Business Directory Plugin for WordPress. It allows unauthorized users to perform actio...
Jun 14, 2024CVE-2023-38395 is a missing authorization vulnerability in the WP Clone Menu WordPress plugin that allows unauthorized users to perform administrative...
Jun 12, 2024This vulnerability allows unauthorized users to access administrative functions in the BulkGate SMS Plugin for WooCommerce due to missing authorizatio...
Jun 12, 2024This CVE describes a Missing Authorization vulnerability in the WordPress 'Import and export users and customers' plugin. It allows unauthorized users...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Simple COD Fees for WooCommerce WordPress plugin. It allows unauthorized users to perf...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Evergreen Content Poster plugin that allows unauthorized users to perform ac...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WPZOOM Social Icons Widget & Block WordPress plugin. It allows attackers to perform un...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in OnTheGoSystems' WooCommerce Multilingual & Multicurrency WordPress plugin. It allows unaut...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the MainWP UpdraftPlus Extension for WordPress. It allows users with Subscriber-level perm...
Jun 9, 2024This vulnerability in the Clever Fox WordPress plugin allows authenticated users with subscriber-level access or higher to change the active theme wit...
Jun 7, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,038 CVEs classified as CWE-862, with 226 rated critical and 846 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free