CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,051)
This CVE describes a Missing Authorization vulnerability in the Brevo Sendinblue for WooCommerce plugin that allows attackers to exploit incorrectly c...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Pochipp plugin that allows attackers to exploit incorrectly configured acces...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the WP Views Counter WordPress plugin that allows attackers to exploit incorrectly configu...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin. It allows attacke...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WP Compress for MainWP WordPress plugin that allows attackers to bypass access control...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the CatFolders WordPress plugin that allows attackers to exploit incorrectly configured ac...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in SiteGround Security plugin for WordPress that allows attackers to exploit incorrectly conf...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the ZEEN101 Leaky Paywall WordPress plugin that allows attackers to bypass access controls...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Auctollo Google XML Sitemaps WordPress plugin (google-sitemap-generator). It allows at...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the OnPay.io for WooCommerce plugin that allows attackers to exploit incorrectly configure...
Dec 16, 2025This vulnerability allows unauthenticated attackers to abuse the JetFormBuilder WordPress plugin's AI form generation feature, consuming the site's AI...
Dec 16, 2025The Dokan Pro WordPress plugin has a missing capability check on its wholesale registration REST API endpoint, allowing unauthenticated attackers to e...
Dec 16, 2025This vulnerability allows unauthenticated attackers to access sensitive order statistics in the LearnPress WordPress plugin, including revenue summari...
Dec 16, 2025This vulnerability allows unauthenticated attackers to modify OneSignal plugin settings in WordPress, including the App ID and API keys. Attackers can...
Dec 15, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to submit replies to any support ticket in the HAPPY He...
Dec 13, 2025The AnnunciFunebri Impresa WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher ...
Dec 13, 2025This vulnerability in the Eyewear prescription form WordPress plugin allows unauthenticated attackers to delete arbitrary WooCommerce product categori...
Dec 13, 2025This vulnerability allows unauthenticated attackers to create arbitrary WooCommerce products with custom names, prices, and categories on WordPress si...
Dec 13, 2025The Easy Theme Options WordPress plugin has a missing authorization vulnerability that allows authenticated attackers with Subscriber-level access or ...
Dec 13, 2025The Devs CRM WordPress plugin has a missing capability check on its bulk-update REST API endpoint, allowing unauthenticated attackers to modify lead t...
Dec 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify tracking settings in the Employee Spotlight p...
Dec 13, 2025This vulnerability allows unauthenticated attackers to manipulate the myCred WordPress plugin's financial systems. Attackers can approve withdrawal re...
Dec 13, 2025The Devs CRM WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to access private user data through a R...
Dec 13, 2025The Simple Bike Rental WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to r...
Dec 12, 2025The PDF for Contact Form 7 + Drag and Drop Template Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users...
Dec 12, 2025This vulnerability allows unauthenticated attackers to write arbitrary JSON files to the server's publicly accessible upload directory via a misconfig...
Dec 12, 2025The Vimeo SimpleGallery WordPress plugin has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or hig...
Dec 12, 2025This vulnerability in the Premmerce Wishlist for WooCommerce WordPress plugin allows authenticated users with Subscriber-level access or higher to del...
Dec 12, 2025This vulnerability in the Filter Plus WooCommerce plugin allows unauthenticated attackers to modify plugin settings and create arbitrary filter option...
Dec 12, 2025This vulnerability allows attackers to bypass authorization controls in the Slider a SlidersPack WordPress plugin, potentially accessing restricted fu...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonate WordPress plugin that allows attackers to bypass access controls....
Dec 9, 2025This CVE describes a missing authorization vulnerability in the rtCamp GoDAM WordPress plugin that allows attackers to bypass access controls. Attacke...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WordPress Highlight and Share plugin that allows attackers to exploit incorrectly conf...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Easy Form Builder WordPress plugin that allows attackers to bypass access controls. It...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WP Email Capture WordPress plugin that allows attackers to bypass access controls. It ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WordPress User Extra Fields plugin (wp-user-extra-fields) that allows attackers to exp...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Constant Contact + WooCommerce WordPress plugin that allows attackers to exploit incor...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the TrueBooker WordPress plugin that allows attackers to bypass access controls. It affect...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Wbcom Designs lock-my-bp WordPress plugin that allows attackers to bypass intended acc...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WPFunnels WordPress plugin that allows attackers to bypass access controls. It affects...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the PenciDesign PenNews WordPress theme that allows attackers to exploit incorrectly confi...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the ThimPress Sailing WordPress theme that allows attackers to bypass access controls. It ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the wpdevart Booking Calendar plugin for WordPress. It allows attackers to bypass access c...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Sitewide Notice WP WordPress plugin that allows attackers to exploit incorrectly confi...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the QuantumCloud Simple Link Directory WordPress plugin that allows attackers to exploit i...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Woffice Core WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the xtemos Basel WordPress theme that allows attackers to bypass access controls. It affec...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the AdForest WordPress theme that allows attackers to bypass access controls. It affects a...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WPForms Google Sheet Connector WordPress plugin that allows attackers to bypass access...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Image Caption Hover Pro WordPress plugin that allows attackers to bypass access contro...
Dec 9, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,051 CVEs classified as CWE-862, with 228 rated critical and 857 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free