CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,049
Total CVEs
228
Critical
855
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 120
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 18
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,049)

CVE-2025-14370
5.3

The Quote Comments WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...

Jan 7, 2026
CVE-2025-14460
5.3

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to c...

Jan 7, 2026
CVE-2025-13722
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary forms via the Fluent Forms AI build...

Jan 7, 2026
CVE-2025-13529
5.3

The Unify WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete specific plugin options. This aff...

Jan 7, 2026
CVE-2025-13496
5.3

The Moosend Landing Pages WordPress plugin up to version 1.1.6 has an authorization vulnerability that allows authenticated users with Subscriber-leve...

Jan 7, 2026
CVE-2025-13419
5.3

This vulnerability in the WP Front User Submit WordPress plugin allows unauthenticated attackers to delete arbitrary media attachments via a REST API ...

Jan 7, 2026
CVE-2025-69364
5.3

This CVE describes a missing authorization vulnerability in the Cloudways Breeze WordPress plugin that allows attackers to bypass access controls. It ...

Jan 6, 2026
CVE-2025-69359
5.3

This CVE describes a missing authorization vulnerability in the WPFunnels Creator LMS WordPress plugin that allows attackers to bypass access controls...

Jan 6, 2026
CVE-2025-11370
5.3

This vulnerability allows unauthenticated attackers to modify pop-up display settings in WordPress sites using the Depicter plugin. All WordPress inst...

Jan 6, 2026
CVE-2025-14047
5.3

This vulnerability in the WP User Frontend WordPress plugin allows unauthenticated attackers to delete attachments without proper authorization. It af...

Jan 2, 2026
CVE-2025-62755
5.3

This vulnerability allows unauthenticated attackers to bypass access controls in the GS Portfolio for Envato WordPress plugin. Attackers can access re...

Dec 31, 2025
CVE-2025-62747
5.3

This CVE describes a Missing Authorization vulnerability in the Aum Watcharapon Featured Image Generator WordPress plugin that allows attackers to byp...

Dec 31, 2025
CVE-2025-62122
5.3

A missing authorization vulnerability in the WordPress Trash Duplicate and 301 Redirect plugin allows attackers to bypass access controls and perform ...

Dec 31, 2025
CVE-2025-62129
5.3

This CVE describes a missing authorization vulnerability in the RestroPress WordPress plugin that allows attackers to bypass access controls. It affec...

Dec 31, 2025
CVE-2025-62092
5.3

CVE-2025-62092 is a missing authorization vulnerability in the Wiremo WordPress plugin that allows attackers to bypass access controls. This affects W...

Dec 31, 2025
CVE-2025-62116
5.3

A missing authorization vulnerability in Quadlayers AI Copilot WordPress plugin allows attackers to bypass access controls and potentially modify plug...

Dec 31, 2025
CVE-2025-49338
5.3

This CVE describes a missing authorization vulnerability in the Flowbox WordPress plugin that allows attackers to bypass access controls. It affects a...

Dec 31, 2025
CVE-2025-62079
5.3

This CVE describes a Missing Authorization vulnerability in the Damian WP Export Categories & Taxonomies WordPress plugin that allows attackers to exp...

Dec 31, 2025
CVE-2025-63016
5.3

This CVE describes a Missing Authorization vulnerability in the QuadLayers TikTok Feed WordPress plugin that allows attackers to bypass access control...

Dec 31, 2025
CVE-2025-63022
5.3

This CVE describes a Missing Authorization vulnerability in the Illia Simple Like Page WordPress plugin that allows attackers to exploit incorrectly c...

Dec 31, 2025
CVE-2025-63031
5.3

This CVE describes a missing authorization vulnerability in the WP Grids EasyTest WordPress plugin that allows attackers to bypass access controls. It...

Dec 31, 2025
CVE-2025-62141
5.3

CVE-2025-62141 is a missing authorization vulnerability in the 101gen Wawp WordPress plugin that allows attackers to bypass access controls and perfor...

Dec 31, 2025
CVE-2025-62145
5.3

A missing authorization vulnerability in the NewClarity DMCA Protection Badge WordPress plugin allows attackers to bypass access controls and perform ...

Dec 31, 2025
CVE-2025-62147
5.3

This CVE describes a Missing Authorization vulnerability in the Realbig WordPress plugin that allows attackers to bypass access controls. It affects a...

Dec 31, 2025
CVE-2025-63001
5.3

This CVE describes a Missing Authorization vulnerability in the nicdark Hotel Booking WordPress plugin that allows attackers to bypass access controls...

Dec 31, 2025
CVE-2025-62081
5.3

This CVE describes a Missing Authorization vulnerability in the Channelize.Io Live Shopping & Shoppable Videos For WooCommerce WordPress plugin. It al...

Dec 31, 2025
CVE-2025-49349
5.3

This CVE describes a missing authorization vulnerability in the Reuters Direct WordPress plugin that allows attackers to bypass access controls. It af...

Dec 31, 2025
CVE-2025-62138
5.3

This vulnerability allows attackers to bypass authorization checks in the WP Advanced PDF WordPress plugin, potentially accessing restricted functiona...

Dec 31, 2025
CVE-2025-66080
5.3

This vulnerability allows attackers to bypass authorization controls in the WP Cookie Notice plugin, potentially accessing administrative functions wi...

Dec 30, 2025
CVE-2025-69093
5.3

This CVE describes a missing authorization vulnerability in the ShopMagic for WooCommerce WordPress plugin that allows attackers to bypass intended ac...

Dec 30, 2025
CVE-2025-69028
5.3

This CVE describes a Missing Authorization vulnerability in BoldGrid weForms WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 30, 2025
CVE-2025-69031
5.3

This CVE describes a Missing Authorization vulnerability in the Skywarrior Arcane WordPress theme that allows attackers to bypass access controls. It ...

Dec 30, 2025
CVE-2025-69009
5.3

This CVE describes a missing authorization vulnerability in the kamleshyadav Medicalequipment WordPress theme that allows attackers to bypass access c...

Dec 30, 2025
CVE-2025-69010
5.3

This CVE describes a Missing Authorization vulnerability in the Themebeez Toolkit WordPress plugin that allows attackers to bypass access controls. It...

Dec 30, 2025
CVE-2025-68993
5.3

This CVE describes a Missing Authorization vulnerability in the XforWooCommerce Share, Print and PDF Products for WooCommerce plugin that allows attac...

Dec 30, 2025
CVE-2025-68994
5.3

This CVE describes a Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce plugin that allows attackers to exploit inco...

Dec 30, 2025
CVE-2025-68556
5.3

This CVE describes a Missing Authorization vulnerability in the VillaTheme HAPPY WordPress plugin that allows attackers to bypass access controls. It ...

Dec 23, 2025
CVE-2025-14155
5.3

This vulnerability allows unauthenticated attackers to view private, draft, and pending Elementor templates in WordPress sites using the Premium Addon...

Dec 23, 2025
CVE-2025-14043
5.3

The Tainacan WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to create arbitrary metadata sections fo...

Dec 21, 2025
CVE-2025-14080
5.3

This vulnerability allows unauthenticated attackers to modify any WordPress post by exploiting missing authorization checks in the Frontend Post Submi...

Dec 21, 2025
CVE-2025-14633
5.3

The F70 Lead Document Download WordPress plugin allows unauthenticated attackers to download any file from the WordPress media library by guessing att...

Dec 20, 2025
CVE-2025-12898
5.3

The Pretty Google Calendar WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to retrieve the Google AP...

Dec 20, 2025
CVE-2025-13754
5.3

This vulnerability allows unauthenticated attackers to access sensitive configuration data from the Simply Schedule Appointments WordPress plugin. All...

Dec 19, 2025
CVE-2025-63002
5.3

A missing authorization vulnerability in wpforchurch Sermon Manager WordPress plugin allows attackers to bypass intended access controls. This affects...

Dec 18, 2025
CVE-2025-54743
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Download After Email plugin that allows unauthorized users to bypass access ...

Dec 18, 2025
CVE-2025-14061
5.3

This vulnerability in the WP Cookie Consent WordPress plugin allows unauthenticated attackers to permanently delete any posts, pages, attachments, or ...

Dec 17, 2025
CVE-2025-67929
5.3

This CVE describes a missing authorization vulnerability in the TI WooCommerce Wishlist WordPress plugin that allows attackers to exploit incorrectly ...

Dec 16, 2025
CVE-2025-67965
5.3

This CVE describes a missing authorization vulnerability in the favethemes Homey Core WordPress plugin that allows attackers to bypass access controls...

Dec 16, 2025
CVE-2025-66128
5.3

This CVE describes a Missing Authorization vulnerability in the Brevo Sendinblue for WooCommerce plugin that allows attackers to exploit incorrectly c...

Dec 16, 2025
CVE-2025-66129
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Pochipp plugin that allows attackers to exploit incorrectly configured acces...

Dec 16, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,049 CVEs classified as CWE-862, with 228 rated critical and 855 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free