CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,044
Total CVEs
226
Critical
852
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 119
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 18
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,044)

CVE-2026-1310
5.3

The Simple calendar for Elementor WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to delete arbitrary...

Jan 28, 2026
CVE-2026-1298
5.3

The Easy Replace Image WordPress plugin has a missing authorization vulnerability that allows authenticated users with Contributor-level access or hig...

Jan 28, 2026
CVE-2025-14971
5.3

This vulnerability in the Link Invoice Payment for WooCommerce WordPress plugin allows unauthenticated attackers to create or cancel partial payments ...

Jan 27, 2026
CVE-2025-14609
5.3

The Wise Analytics WordPress plugin up to version 1.1.9 has a missing authorization vulnerability in its REST API endpoint. Unauthenticated attackers ...

Jan 24, 2026
CVE-2025-14629
5.3

The Alchemist Ajax Upload WordPress plugin allows unauthenticated attackers to delete arbitrary media attachments due to missing capability checks. Th...

Jan 24, 2026
CVE-2026-24583
5.3

This CVE describes a missing authorization vulnerability in the SumUp Payment Gateway for WooCommerce plugin that allows attackers to bypass access co...

Jan 23, 2026
CVE-2026-24577
5.3

This CVE describes a Missing Authorization vulnerability in the Pie Register WordPress plugin that allows attackers to bypass access controls. It affe...

Jan 23, 2026
CVE-2026-24568
5.3

This CVE describes a missing authorization vulnerability in the WP Travel WordPress plugin that allows attackers to exploit incorrectly configured acc...

Jan 23, 2026
CVE-2026-24562
5.3

This CVE describes a Missing Authorization vulnerability in the Ryviu Product Reviews for WooCommerce WordPress plugin. It allows attackers to exploit...

Jan 23, 2026
CVE-2026-24556
5.3

This CVE describes a Missing Authorization vulnerability in the ElementCamp WordPress plugin that allows attackers to bypass access controls. It affec...

Jan 23, 2026
CVE-2026-24539
5.3

This CVE describes a missing authorization vulnerability in the ABCdatos Protección de datos - RGPD WordPress plugin that allows attackers to bypass ...

Jan 23, 2026
CVE-2026-24541
5.3

This CVE describes a missing authorization vulnerability in the WordPress Download After Email plugin that allows unauthorized users to bypass access ...

Jan 23, 2026
CVE-2026-24525
5.3

This vulnerability allows unauthorized users to exploit incorrectly configured access control in CloudPanel CLP Varnish Cache, potentially accessing r...

Jan 23, 2026
CVE-2026-24529
5.3

This CVE describes a Missing Authorization vulnerability in the Quick Restaurant Reservations WordPress plugin that allows attackers to bypass access ...

Jan 23, 2026
CVE-2026-24530
5.3

This CVE describes a Missing Authorization vulnerability in the sheepfish WebP Conversion WordPress plugin that allows attackers to bypass access cont...

Jan 23, 2026
CVE-2026-0927
5.3

The KiviCare WordPress plugin allows unauthenticated attackers to upload arbitrary text and PDF files due to missing authorization checks. This affect...

Jan 23, 2026
CVE-2026-24366
5.3

This CVE describes a Missing Authorization vulnerability in YITH WooCommerce Request A Quote plugin that allows attackers to bypass access controls. I...

Jan 22, 2026
CVE-2026-22445
5.3

This CVE describes a missing authorization vulnerability in the Apimo Connector WordPress plugin that allows attackers to bypass access controls. Atta...

Jan 22, 2026
CVE-2026-22447
5.3

This CVE describes a Missing Authorization vulnerability in the Prowess WordPress theme that allows attackers to bypass access controls. It affects al...

Jan 22, 2026
CVE-2026-22458
5.3

This CVE describes a Missing Authorization vulnerability in the Mikado-Themes Wanderland WordPress theme that allows attackers to bypass access contro...

Jan 22, 2026
CVE-2026-22461
5.3

This CVE describes a Missing Authorization vulnerability in the WebAppick CTX Feed plugin for WooCommerce, allowing unauthorized users to exploit inco...

Jan 22, 2026
CVE-2026-22348
5.3

This CVE describes a missing authorization vulnerability in the Civic Cookie Control WordPress plugin that allows attackers to bypass access controls....

Jan 22, 2026
CVE-2026-1036
5.3

This vulnerability in the Photo Gallery by 10WordPress plugin allows unauthenticated attackers to delete arbitrary image comments due to missing capab...

Jan 22, 2026
CVE-2025-14351
5.3

This vulnerability in the Custom Fonts WordPress plugin allows unauthenticated attackers to delete font directories and rewrite theme.json files due t...

Jan 20, 2026
CVE-2025-14798
5.3

The LearnPress WordPress plugin up to version 4.3.2.4 has an API endpoint that doesn't properly check user permissions, allowing unauthenticated attac...

Jan 20, 2026
CVE-2025-14978
5.3

The PeachPay WooCommerce plugin has a missing capability check on its ConvesioPay webhook endpoint, allowing unauthenticated attackers to modify WooCo...

Jan 20, 2026
CVE-2025-14078
5.3

The PAYGENT for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to send forged payment no...

Jan 17, 2026
CVE-2025-14029
5.3

The Community Events WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to approve arbitrary events wit...

Jan 17, 2026
CVE-2025-12825
5.3

The User Registration Using Contact Form 7 WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to retriev...

Jan 17, 2026
CVE-2026-0820
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary signatures to any order in the Repa...

Jan 17, 2026
CVE-2025-14463
5.3

The Payment Button for PayPal WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create fake orders ...

Jan 17, 2026
CVE-2026-1004
5.3

The Essential Addons for Elementor WordPress plugin exposes draft, pending, and private WooCommerce product information to unauthenticated attackers t...

Jan 16, 2026
CVE-2025-14757
5.3

This vulnerability allows unauthenticated attackers to mark any order's payment status as 'completed' without actual payment in WordPress sites using ...

Jan 16, 2026
CVE-2025-12895
5.3

This vulnerability allows unauthenticated attackers to use the Kalium WordPress theme as an open mail relay, sending emails from the server without au...

Jan 15, 2026
CVE-2025-15475
5.3

This vulnerability allows unauthenticated attackers to manipulate WooCommerce order statuses through the PayHere Payment Gateway plugin. Attackers can...

Jan 14, 2026
CVE-2025-15512
5.3

The Aplazo Payment Gateway WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to change WooCommerce orde...

Jan 14, 2026
CVE-2025-14173
5.3

The Perfit WooCommerce plugin for WordPress has a missing authorization vulnerability that allows unauthenticated attackers to delete arbitrary plugin...

Jan 14, 2026
CVE-2025-14880
5.3

The Netcash WooCommerce Payment Gateway plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to mark ...

Jan 14, 2026
CVE-2025-14948
5.3

The miniOrange OTP Verification and SMS Notification for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenti...

Jan 10, 2026
CVE-2026-0817
5.3

A missing authorization vulnerability in MediaWiki's CampaignEvents extension allows authenticated users to perform privileged actions without proper ...

Jan 9, 2026
CVE-2025-13717
5.3

This vulnerability allows unauthenticated attackers to export sensitive Contact Form 7 submission data from WordPress sites using the Contact Form vCa...

Jan 9, 2026
CVE-2025-14146
5.3

The Booking Calendar WordPress plugin exposes sensitive booking data to unauthenticated attackers due to disabled nonce verification by default. When ...

Jan 9, 2026
CVE-2026-22488
5.3

This CVE describes a Missing Authorization vulnerability in the Dashboard Welcome for Beaver Builder WordPress plugin. It allows attackers to exploit ...

Jan 8, 2026
CVE-2026-22486
5.3

This CVE describes a Missing Authorization vulnerability in the Hakob Re Gallery & Responsive Photo Gallery WordPress plugin. It allows attackers to b...

Jan 8, 2026
CVE-2026-0676
5.3

This CVE describes a Missing Authorization vulnerability in the Zorka WordPress theme by G5Theme, allowing attackers to exploit incorrectly configured...

Jan 8, 2026
CVE-2025-14370
5.3

The Quote Comments WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...

Jan 7, 2026
CVE-2025-14460
5.3

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to c...

Jan 7, 2026
CVE-2025-13722
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary forms via the Fluent Forms AI build...

Jan 7, 2026
CVE-2025-13529
5.3

The Unify WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete specific plugin options. This aff...

Jan 7, 2026
CVE-2025-13496
5.3

The Moosend Landing Pages WordPress plugin up to version 1.1.6 has an authorization vulnerability that allows authenticated users with Subscriber-leve...

Jan 7, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,044 CVEs classified as CWE-862, with 226 rated critical and 852 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free