CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,051)
This CVE describes a Missing Authorization vulnerability in the Post SMTP WordPress plugin that allows attackers to exploit incorrectly configured acc...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Ivory Search WordPress plugin that allows attackers to exploit incorrectly configured ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. Attackers ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WordPress ListingPro Lead Form plugin that allows attackers to access functionality no...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Quiz And Survey Master WordPress plugin that allows attackers to bypass access control...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Traveler WordPress theme that allows attackers to bypass access controls. Attackers co...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Payment Gateway for PayPal on WooCommerce plugin that allows attackers to exploit inco...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in weDevs WP ERP plugin for WordPress that allows attackers to exploit incorrectly configured...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Eupago Gateway for WooCommerce WordPress plugin that allows attackers to bypass access...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Post Cloner plugin that allows attackers to exploit incorrectly configured a...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Formstack Online Forms WordPress plugin that allows attackers to bypass access control...
Dec 9, 2025This vulnerability allows unauthorized users to access CRM data and functions due to broken access controls in the WP-CRM System WordPress plugin. Any...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to bypass access controls. It affects...
Dec 9, 2025This vulnerability allows attackers to bypass authorization controls in the ThemeRain Core WordPress plugin, potentially accessing restricted function...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Hype Hype pico WordPress plugin that allows attackers to bypass access controls. It af...
Dec 9, 2025This vulnerability allows unauthenticated attackers to clear or overwrite the social counter cache in the Wp Social Login and Register Social Counter ...
Dec 5, 2025The Projectopia WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary file attachments...
Dec 5, 2025The Everest Backup WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete backup progress files. ...
Dec 3, 2025This vulnerability in TCMAN GIM v11 allows unauthenticated attackers to determine whether specific user accounts exist on the system by exploiting a S...
Dec 2, 2025The Hide Category by User Role for WooCommerce WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to flu...
Nov 27, 2025The atec Duplicate Page & Post WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or hi...
Nov 25, 2025The Ace Post Type Builder WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or hig...
Nov 25, 2025The Chamber Dashboard Business Directory WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export al...
Nov 25, 2025The Social Images Widget WordPress plugin has a missing capability check that allows unauthenticated attackers to delete plugin settings via CSRF. Thi...
Nov 25, 2025The Autochat Automatic Conversation WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify client...
Nov 25, 2025The Booking Calendar Contact Form WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to confirm bookings...
Nov 22, 2025This vulnerability allows unauthenticated attackers to arbitrarily confirm appointments in the Appointment Booking Calendar WordPress plugin without p...
Nov 22, 2025This vulnerability allows unauthorized users to access WooCommerce product variation data due to missing authorization checks in the 'Show Variations ...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the Subscriptions & Memberships for PayPal WordPress plugin that allows attackers to bypas...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the Cart Weight for WooCommerce plugin that allows attackers to bypass access controls. It...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the bPlugins Tiktok Feed WordPress plugin (b-tiktok-feed) that allows attackers to exploit...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the ThemeAtelier Chat Help WordPress plugin that allows attackers to bypass access control...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the Cozy Vision SMS Alert Order Notifications WordPress plugin that allows attackers to by...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the PropertyHive WordPress plugin that allows attackers to bypass access controls. It affe...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the Custom Order Numbers for WooCommerce WordPress plugin that allows unauthorized users t...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the Gutenverse WordPress plugin that allows attackers to bypass access controls. It affect...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the Seriously Simple Podcasting WordPress plugin that allows attackers to bypass access co...
Nov 21, 2025The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to remove...
Nov 21, 2025The Checkbox plugin for WordPress has an unauthenticated AJAX endpoint that allows attackers to clear log files without proper authorization. This aff...
Nov 21, 2025This vulnerability allows unauthenticated attackers to extract partial metadata of all WordPress users, including first names, last names, and email a...
Nov 20, 2025The Restrictions for BuddyPress WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify user track...
Nov 18, 2025The Cryptocurrency Payment Gateway for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to...
Nov 18, 2025The Contest Gallery WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to inject arbitrary media attachm...
Nov 15, 2025This CVE describes a Missing Authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....
Nov 13, 2025This CVE describes a missing authorization vulnerability in the YOP Poll WordPress plugin that allows attackers to exploit incorrectly configured acce...
Nov 13, 2025The Survey Maker WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to view all survey submissions. Thi...
Nov 13, 2025The Survey Maker WordPress plugin allows unauthenticated attackers to modify the ays_survey_maker_upgrade_plugin option due to missing capability chec...
Nov 13, 2025The Welcart e-Commerce plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive payme...
Nov 13, 2025NVIDIA AIStore has an authentication vulnerability (CWE-862: Missing Authorization) that allows unauthenticated attackers to access sensitive informat...
Nov 11, 2025The Find Unused Images WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete all image attachment...
Nov 11, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,051 CVEs classified as CWE-862, with 228 rated critical and 857 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free