CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,051
Total CVEs
228
Critical
857
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 122
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 18
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,051)

CVE-2025-66128
5.3

This CVE describes a Missing Authorization vulnerability in the Brevo Sendinblue for WooCommerce plugin that allows attackers to exploit incorrectly c...

Dec 16, 2025
CVE-2025-66129
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Pochipp plugin that allows attackers to exploit incorrectly configured acces...

Dec 16, 2025
CVE-2025-66130
5.3

This CVE describes a Missing Authorization vulnerability in the WP Views Counter WordPress plugin that allows attackers to exploit incorrectly configu...

Dec 16, 2025
CVE-2025-66133
5.3

This CVE describes a missing authorization vulnerability in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin. It allows attacke...

Dec 16, 2025
CVE-2025-64639
5.3

This CVE describes a missing authorization vulnerability in the WP Compress for MainWP WordPress plugin that allows attackers to bypass access control...

Dec 16, 2025
CVE-2025-66120
5.3

This CVE describes a missing authorization vulnerability in the CatFolders WordPress plugin that allows attackers to exploit incorrectly configured ac...

Dec 16, 2025
CVE-2025-66121
5.3

This CVE describes a Missing Authorization vulnerability in SiteGround Security plugin for WordPress that allows attackers to exploit incorrectly conf...

Dec 16, 2025
CVE-2025-66124
5.3

This CVE describes a Missing Authorization vulnerability in the ZEEN101 Leaky Paywall WordPress plugin that allows attackers to bypass access controls...

Dec 16, 2025
CVE-2025-64632
5.3

This CVE describes a Missing Authorization vulnerability in the Auctollo Google XML Sitemaps WordPress plugin (google-sitemap-generator). It allows at...

Dec 16, 2025
CVE-2025-64638
5.3

This CVE describes a Missing Authorization vulnerability in the OnPay.io for WooCommerce plugin that allows attackers to exploit incorrectly configure...

Dec 16, 2025
CVE-2025-11991
5.3

This vulnerability allows unauthenticated attackers to abuse the JetFormBuilder WordPress plugin's AI form generation feature, consuming the site's AI...

Dec 16, 2025
CVE-2025-12809
5.3

The Dokan Pro WordPress plugin has a missing capability check on its wholesale registration REST API endpoint, allowing unauthenticated attackers to e...

Dec 16, 2025
CVE-2025-13956
5.3

This vulnerability allows unauthenticated attackers to access sensitive order statistics in the LearnPress WordPress plugin, including revenue summari...

Dec 16, 2025
CVE-2025-13950
5.3

This vulnerability allows unauthenticated attackers to modify OneSignal plugin settings in WordPress, including the App ID and API keys. Attackers can...

Dec 15, 2025
CVE-2025-14581
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to submit replies to any support ticket in the HAPPY He...

Dec 13, 2025
CVE-2025-14447
5.3

The AnnunciFunebri Impresa WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher ...

Dec 13, 2025
CVE-2025-14365
5.3

This vulnerability in the Eyewear prescription form WordPress plugin allows unauthenticated attackers to delete arbitrary WooCommerce product categori...

Dec 13, 2025
CVE-2025-14366
5.3

This vulnerability allows unauthenticated attackers to create arbitrary WooCommerce products with custom names, prices, and categories on WordPress si...

Dec 13, 2025
CVE-2025-14367
5.3

The Easy Theme Options WordPress plugin has a missing authorization vulnerability that allows authenticated attackers with Subscriber-level access or ...

Dec 13, 2025
CVE-2025-13093
5.3

The Devs CRM WordPress plugin has a missing capability check on its bulk-update REST API endpoint, allowing unauthenticated attackers to modify lead t...

Dec 13, 2025
CVE-2025-13403
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify tracking settings in the Employee Spotlight p...

Dec 13, 2025
CVE-2025-12362
5.3

This vulnerability allows unauthenticated attackers to manipulate the myCred WordPress plugin's financial systems. Attackers can approve withdrawal re...

Dec 13, 2025
CVE-2025-13092
5.3

The Devs CRM WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to access private user data through a R...

Dec 13, 2025
CVE-2025-14065
5.3

The Simple Bike Rental WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to r...

Dec 12, 2025
CVE-2025-14074
5.3

The PDF for Contact Form 7 + Drag and Drop Template Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users...

Dec 12, 2025
CVE-2025-12655
5.3

This vulnerability allows unauthenticated attackers to write arbitrary JSON files to the server's publicly accessible upload directory via a misconfig...

Dec 12, 2025
CVE-2025-14170
5.3

The Vimeo SimpleGallery WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or hig...

Dec 12, 2025
CVE-2025-13440
5.3

This vulnerability in the Premmerce Wishlist for WooCommerce WordPress plugin allows authenticated users with Subscriber-level access or higher to del...

Dec 12, 2025
CVE-2025-13314
5.3

This vulnerability in the Filter Plus WooCommerce plugin allows unauthenticated attackers to modify plugin settings and create arbitrary filter option...

Dec 12, 2025
CVE-2022-46845
5.3

This vulnerability allows attackers to bypass authorization controls in the Slider a SlidersPack WordPress plugin, potentially accessing restricted fu...

Dec 9, 2025
CVE-2025-67583
5.3

This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonate WordPress plugin that allows attackers to bypass access controls....

Dec 9, 2025
CVE-2025-67584
5.3

This CVE describes a missing authorization vulnerability in the rtCamp GoDAM WordPress plugin that allows attackers to bypass access controls. Attacke...

Dec 9, 2025
CVE-2025-67586
5.3

This CVE describes a missing authorization vulnerability in the WordPress Highlight and Share plugin that allows attackers to exploit incorrectly conf...

Dec 9, 2025
CVE-2025-67577
5.3

This CVE describes a missing authorization vulnerability in the Easy Form Builder WordPress plugin that allows attackers to bypass access controls. It...

Dec 9, 2025
CVE-2025-67578
5.3

This CVE describes a missing authorization vulnerability in the WP Email Capture WordPress plugin that allows attackers to bypass access controls. It ...

Dec 9, 2025
CVE-2025-67579
5.3

This CVE describes a missing authorization vulnerability in the WordPress User Extra Fields plugin (wp-user-extra-fields) that allows attackers to exp...

Dec 9, 2025
CVE-2025-67580
5.3

This CVE describes a missing authorization vulnerability in the Constant Contact + WooCommerce WordPress plugin that allows attackers to exploit incor...

Dec 9, 2025
CVE-2025-67581
5.3

This CVE describes a Missing Authorization vulnerability in the TrueBooker WordPress plugin that allows attackers to bypass access controls. It affect...

Dec 9, 2025
CVE-2025-67582
5.3

This CVE describes a missing authorization vulnerability in the Wbcom Designs lock-my-bp WordPress plugin that allows attackers to bypass intended acc...

Dec 9, 2025
CVE-2025-67571
5.3

This CVE describes a missing authorization vulnerability in the WPFunnels WordPress plugin that allows attackers to bypass access controls. It affects...

Dec 9, 2025
CVE-2025-67572
5.3

This CVE describes a missing authorization vulnerability in the PenciDesign PenNews WordPress theme that allows attackers to exploit incorrectly confi...

Dec 9, 2025
CVE-2025-67573
5.3

This CVE describes a missing authorization vulnerability in the ThimPress Sailing WordPress theme that allows attackers to bypass access controls. It ...

Dec 9, 2025
CVE-2025-67574
5.3

This CVE describes a missing authorization vulnerability in the wpdevart Booking Calendar plugin for WordPress. It allows attackers to bypass access c...

Dec 9, 2025
CVE-2025-67575
5.3

This CVE describes a Missing Authorization vulnerability in the Sitewide Notice WP WordPress plugin that allows attackers to exploit incorrectly confi...

Dec 9, 2025
CVE-2025-67576
5.3

This CVE describes a missing authorization vulnerability in the QuantumCloud Simple Link Directory WordPress plugin that allows attackers to exploit i...

Dec 9, 2025
CVE-2025-67566
5.3

This CVE describes a missing authorization vulnerability in the Woffice Core WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 9, 2025
CVE-2025-67568
5.3

This CVE describes a missing authorization vulnerability in the xtemos Basel WordPress theme that allows attackers to bypass access controls. It affec...

Dec 9, 2025
CVE-2025-67569
5.3

This CVE describes a Missing Authorization vulnerability in the AdForest WordPress theme that allows attackers to bypass access controls. It affects a...

Dec 9, 2025
CVE-2025-67570
5.3

This CVE describes a missing authorization vulnerability in the WPForms Google Sheet Connector WordPress plugin that allows attackers to bypass access...

Dec 9, 2025
CVE-2025-67562
5.3

This CVE describes a missing authorization vulnerability in the Image Caption Hover Pro WordPress plugin that allows attackers to bypass access contro...

Dec 9, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,051 CVEs classified as CWE-862, with 228 rated critical and 857 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free