CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,044)
The Simple calendar for Elementor WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to delete arbitrary...
Jan 28, 2026The Easy Replace Image WordPress plugin has a missing authorization vulnerability that allows authenticated users with Contributor-level access or hig...
Jan 28, 2026This vulnerability in the Link Invoice Payment for WooCommerce WordPress plugin allows unauthenticated attackers to create or cancel partial payments ...
Jan 27, 2026The Wise Analytics WordPress plugin up to version 1.1.9 has a missing authorization vulnerability in its REST API endpoint. Unauthenticated attackers ...
Jan 24, 2026The Alchemist Ajax Upload WordPress plugin allows unauthenticated attackers to delete arbitrary media attachments due to missing capability checks. Th...
Jan 24, 2026This CVE describes a missing authorization vulnerability in the SumUp Payment Gateway for WooCommerce plugin that allows attackers to bypass access co...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Pie Register WordPress plugin that allows attackers to bypass access controls. It affe...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the WP Travel WordPress plugin that allows attackers to exploit incorrectly configured acc...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Ryviu Product Reviews for WooCommerce WordPress plugin. It allows attackers to exploit...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the ElementCamp WordPress plugin that allows attackers to bypass access controls. It affec...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the ABCdatos Protección de datos - RGPD WordPress plugin that allows attackers to bypass ...
Jan 23, 2026This CVE describes a missing authorization vulnerability in the WordPress Download After Email plugin that allows unauthorized users to bypass access ...
Jan 23, 2026This vulnerability allows unauthorized users to exploit incorrectly configured access control in CloudPanel CLP Varnish Cache, potentially accessing r...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the Quick Restaurant Reservations WordPress plugin that allows attackers to bypass access ...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in the sheepfish WebP Conversion WordPress plugin that allows attackers to bypass access cont...
Jan 23, 2026The KiviCare WordPress plugin allows unauthenticated attackers to upload arbitrary text and PDF files due to missing authorization checks. This affect...
Jan 23, 2026This CVE describes a Missing Authorization vulnerability in YITH WooCommerce Request A Quote plugin that allows attackers to bypass access controls. I...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Apimo Connector WordPress plugin that allows attackers to bypass access controls. Atta...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Prowess WordPress theme that allows attackers to bypass access controls. It affects al...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Mikado-Themes Wanderland WordPress theme that allows attackers to bypass access contro...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the WebAppick CTX Feed plugin for WooCommerce, allowing unauthorized users to exploit inco...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Civic Cookie Control WordPress plugin that allows attackers to bypass access controls....
Jan 22, 2026This vulnerability in the Photo Gallery by 10WordPress plugin allows unauthenticated attackers to delete arbitrary image comments due to missing capab...
Jan 22, 2026This vulnerability in the Custom Fonts WordPress plugin allows unauthenticated attackers to delete font directories and rewrite theme.json files due t...
Jan 20, 2026The LearnPress WordPress plugin up to version 4.3.2.4 has an API endpoint that doesn't properly check user permissions, allowing unauthenticated attac...
Jan 20, 2026The PeachPay WooCommerce plugin has a missing capability check on its ConvesioPay webhook endpoint, allowing unauthenticated attackers to modify WooCo...
Jan 20, 2026The PAYGENT for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to send forged payment no...
Jan 17, 2026The Community Events WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to approve arbitrary events wit...
Jan 17, 2026The User Registration Using Contact Form 7 WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to retriev...
Jan 17, 2026This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary signatures to any order in the Repa...
Jan 17, 2026The Payment Button for PayPal WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create fake orders ...
Jan 17, 2026The Essential Addons for Elementor WordPress plugin exposes draft, pending, and private WooCommerce product information to unauthenticated attackers t...
Jan 16, 2026This vulnerability allows unauthenticated attackers to mark any order's payment status as 'completed' without actual payment in WordPress sites using ...
Jan 16, 2026This vulnerability allows unauthenticated attackers to use the Kalium WordPress theme as an open mail relay, sending emails from the server without au...
Jan 15, 2026This vulnerability allows unauthenticated attackers to manipulate WooCommerce order statuses through the PayHere Payment Gateway plugin. Attackers can...
Jan 14, 2026The Aplazo Payment Gateway WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to change WooCommerce orde...
Jan 14, 2026The Perfit WooCommerce plugin for WordPress has a missing authorization vulnerability that allows unauthenticated attackers to delete arbitrary plugin...
Jan 14, 2026The Netcash WooCommerce Payment Gateway plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to mark ...
Jan 14, 2026The miniOrange OTP Verification and SMS Notification for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenti...
Jan 10, 2026A missing authorization vulnerability in MediaWiki's CampaignEvents extension allows authenticated users to perform privileged actions without proper ...
Jan 9, 2026This vulnerability allows unauthenticated attackers to export sensitive Contact Form 7 submission data from WordPress sites using the Contact Form vCa...
Jan 9, 2026The Booking Calendar WordPress plugin exposes sensitive booking data to unauthenticated attackers due to disabled nonce verification by default. When ...
Jan 9, 2026This CVE describes a Missing Authorization vulnerability in the Dashboard Welcome for Beaver Builder WordPress plugin. It allows attackers to exploit ...
Jan 8, 2026This CVE describes a Missing Authorization vulnerability in the Hakob Re Gallery & Responsive Photo Gallery WordPress plugin. It allows attackers to b...
Jan 8, 2026This CVE describes a Missing Authorization vulnerability in the Zorka WordPress theme by G5Theme, allowing attackers to exploit incorrectly configured...
Jan 8, 2026The Quote Comments WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...
Jan 7, 2026The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to c...
Jan 7, 2026This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary forms via the Fluent Forms AI build...
Jan 7, 2026The Unify WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete specific plugin options. This aff...
Jan 7, 2026The Moosend Landing Pages WordPress plugin up to version 1.1.6 has an authorization vulnerability that allows authenticated users with Subscriber-leve...
Jan 7, 2026About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,044 CVEs classified as CWE-862, with 226 rated critical and 852 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free