CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,049)
The Quote Comments WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...
Jan 7, 2026The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to c...
Jan 7, 2026This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary forms via the Fluent Forms AI build...
Jan 7, 2026The Unify WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete specific plugin options. This aff...
Jan 7, 2026The Moosend Landing Pages WordPress plugin up to version 1.1.6 has an authorization vulnerability that allows authenticated users with Subscriber-leve...
Jan 7, 2026This vulnerability in the WP Front User Submit WordPress plugin allows unauthenticated attackers to delete arbitrary media attachments via a REST API ...
Jan 7, 2026This CVE describes a missing authorization vulnerability in the Cloudways Breeze WordPress plugin that allows attackers to bypass access controls. It ...
Jan 6, 2026This CVE describes a missing authorization vulnerability in the WPFunnels Creator LMS WordPress plugin that allows attackers to bypass access controls...
Jan 6, 2026This vulnerability allows unauthenticated attackers to modify pop-up display settings in WordPress sites using the Depicter plugin. All WordPress inst...
Jan 6, 2026This vulnerability in the WP User Frontend WordPress plugin allows unauthenticated attackers to delete attachments without proper authorization. It af...
Jan 2, 2026This vulnerability allows unauthenticated attackers to bypass access controls in the GS Portfolio for Envato WordPress plugin. Attackers can access re...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Aum Watcharapon Featured Image Generator WordPress plugin that allows attackers to byp...
Dec 31, 2025A missing authorization vulnerability in the WordPress Trash Duplicate and 301 Redirect plugin allows attackers to bypass access controls and perform ...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the RestroPress WordPress plugin that allows attackers to bypass access controls. It affec...
Dec 31, 2025CVE-2025-62092 is a missing authorization vulnerability in the Wiremo WordPress plugin that allows attackers to bypass access controls. This affects W...
Dec 31, 2025A missing authorization vulnerability in Quadlayers AI Copilot WordPress plugin allows attackers to bypass access controls and potentially modify plug...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the Flowbox WordPress plugin that allows attackers to bypass access controls. It affects a...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Damian WP Export Categories & Taxonomies WordPress plugin that allows attackers to exp...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the QuadLayers TikTok Feed WordPress plugin that allows attackers to bypass access control...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Illia Simple Like Page WordPress plugin that allows attackers to exploit incorrectly c...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the WP Grids EasyTest WordPress plugin that allows attackers to bypass access controls. It...
Dec 31, 2025CVE-2025-62141 is a missing authorization vulnerability in the 101gen Wawp WordPress plugin that allows attackers to bypass access controls and perfor...
Dec 31, 2025A missing authorization vulnerability in the NewClarity DMCA Protection Badge WordPress plugin allows attackers to bypass access controls and perform ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Realbig WordPress plugin that allows attackers to bypass access controls. It affects a...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the nicdark Hotel Booking WordPress plugin that allows attackers to bypass access controls...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Channelize.Io Live Shopping & Shoppable Videos For WooCommerce WordPress plugin. It al...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the Reuters Direct WordPress plugin that allows attackers to bypass access controls. It af...
Dec 31, 2025This vulnerability allows attackers to bypass authorization checks in the WP Advanced PDF WordPress plugin, potentially accessing restricted functiona...
Dec 31, 2025This vulnerability allows attackers to bypass authorization controls in the WP Cookie Notice plugin, potentially accessing administrative functions wi...
Dec 30, 2025This CVE describes a missing authorization vulnerability in the ShopMagic for WooCommerce WordPress plugin that allows attackers to bypass intended ac...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in BoldGrid weForms WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Skywarrior Arcane WordPress theme that allows attackers to bypass access controls. It ...
Dec 30, 2025This CVE describes a missing authorization vulnerability in the kamleshyadav Medicalequipment WordPress theme that allows attackers to bypass access c...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Themebeez Toolkit WordPress plugin that allows attackers to bypass access controls. It...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the XforWooCommerce Share, Print and PDF Products for WooCommerce plugin that allows attac...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce plugin that allows attackers to exploit inco...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the VillaTheme HAPPY WordPress plugin that allows attackers to bypass access controls. It ...
Dec 23, 2025This vulnerability allows unauthenticated attackers to view private, draft, and pending Elementor templates in WordPress sites using the Premium Addon...
Dec 23, 2025The Tainacan WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to create arbitrary metadata sections fo...
Dec 21, 2025This vulnerability allows unauthenticated attackers to modify any WordPress post by exploiting missing authorization checks in the Frontend Post Submi...
Dec 21, 2025The F70 Lead Document Download WordPress plugin allows unauthenticated attackers to download any file from the WordPress media library by guessing att...
Dec 20, 2025The Pretty Google Calendar WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to retrieve the Google AP...
Dec 20, 2025This vulnerability allows unauthenticated attackers to access sensitive configuration data from the Simply Schedule Appointments WordPress plugin. All...
Dec 19, 2025A missing authorization vulnerability in wpforchurch Sermon Manager WordPress plugin allows attackers to bypass intended access controls. This affects...
Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Download After Email plugin that allows unauthorized users to bypass access ...
Dec 18, 2025This vulnerability in the WP Cookie Consent WordPress plugin allows unauthenticated attackers to permanently delete any posts, pages, attachments, or ...
Dec 17, 2025This CVE describes a missing authorization vulnerability in the TI WooCommerce Wishlist WordPress plugin that allows attackers to exploit incorrectly ...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the favethemes Homey Core WordPress plugin that allows attackers to bypass access controls...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Brevo Sendinblue for WooCommerce plugin that allows attackers to exploit incorrectly c...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Pochipp plugin that allows attackers to exploit incorrectly configured acces...
Dec 16, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,049 CVEs classified as CWE-862, with 228 rated critical and 855 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free