CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,051
Total CVEs
228
Critical
857
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 122
2 Sap 35
3 Apple 27
4 Jenkins 22
5 Gitlab 18
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,051)

CVE-2025-67563
5.3

This CVE describes a Missing Authorization vulnerability in the Post SMTP WordPress plugin that allows attackers to exploit incorrectly configured acc...

Dec 9, 2025
CVE-2025-63069
5.3

This CVE describes a missing authorization vulnerability in the Ivory Search WordPress plugin that allows attackers to exploit incorrectly configured ...

Dec 9, 2025
CVE-2025-63047
5.3

This CVE describes a missing authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. Attackers ...

Dec 9, 2025
CVE-2025-63049
5.3

This CVE describes a missing authorization vulnerability in the WordPress ListingPro Lead Form plugin that allows attackers to access functionality no...

Dec 9, 2025
CVE-2025-63054
5.3

This CVE describes a missing authorization vulnerability in the Quiz And Survey Master WordPress plugin that allows attackers to bypass access control...

Dec 9, 2025
CVE-2025-63028
5.3

This CVE describes a missing authorization vulnerability in the Traveler WordPress theme that allows attackers to bypass access controls. Attackers co...

Dec 9, 2025
CVE-2025-63023
5.3

This CVE describes a Missing Authorization vulnerability in the Payment Gateway for PayPal on WooCommerce plugin that allows attackers to exploit inco...

Dec 9, 2025
CVE-2025-63008
5.3

This CVE describes a Missing Authorization vulnerability in weDevs WP ERP plugin for WordPress that allows attackers to exploit incorrectly configured...

Dec 9, 2025
CVE-2025-62870
5.3

This CVE describes a Missing Authorization vulnerability in the Eupago Gateway for WooCommerce WordPress plugin that allows attackers to bypass access...

Dec 9, 2025
CVE-2025-62865
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Post Cloner plugin that allows attackers to exploit incorrectly configured a...

Dec 9, 2025
CVE-2025-62738
5.3

This CVE describes a Missing Authorization vulnerability in the Formstack Online Forms WordPress plugin that allows attackers to bypass access control...

Dec 9, 2025
CVE-2025-62740
5.3

This vulnerability allows unauthorized users to access CRM data and functions due to broken access controls in the WP-CRM System WordPress plugin. Any...

Dec 9, 2025
CVE-2025-62085
5.3

This CVE describes a Missing Authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to bypass access controls. It affects...

Dec 9, 2025
CVE-2025-62100
5.3

This vulnerability allows attackers to bypass authorization controls in the ThemeRain Core WordPress plugin, potentially accessing restricted function...

Dec 9, 2025
CVE-2025-49348
5.3

This CVE describes a Missing Authorization vulnerability in the Hype Hype pico WordPress plugin that allows attackers to bypass access controls. It af...

Dec 9, 2025
CVE-2025-13620
5.3

This vulnerability allows unauthenticated attackers to clear or overwrite the social counter cache in the Wp Social Login and Register Social Counter ...

Dec 5, 2025
CVE-2025-12876
5.3

The Projectopia WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary file attachments...

Dec 5, 2025
CVE-2025-10304
5.3

The Everest Backup WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete backup progress files. ...

Dec 3, 2025
CVE-2025-41012
5.3

This vulnerability in TCMAN GIM v11 allows unauthenticated attackers to determine whether specific user accounts exist on the system by exploiting a S...

Dec 2, 2025
CVE-2025-13441
5.3

The Hide Category by User Role for WooCommerce WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to flu...

Nov 27, 2025
CVE-2025-13404
5.3

The atec Duplicate Page & Post WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or hi...

Nov 25, 2025
CVE-2025-13405
5.3

The Ace Post Type Builder WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or hig...

Nov 25, 2025
CVE-2025-13414
5.3

The Chamber Dashboard Business Directory WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export al...

Nov 25, 2025
CVE-2025-13386
5.3

The Social Images Widget WordPress plugin has a missing capability check that allows unauthenticated attackers to delete plugin settings via CSRF. Thi...

Nov 25, 2025
CVE-2025-12043
5.3

The Autochat Automatic Conversation WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify client...

Nov 25, 2025
CVE-2025-13318
5.3

The Booking Calendar Contact Form WordPress plugin has a missing authorization vulnerability that allows unauthenticated attackers to confirm bookings...

Nov 22, 2025
CVE-2025-13317
5.3

This vulnerability allows unauthenticated attackers to arbitrarily confirm appointments in the Appointment Booking Calendar WordPress plugin without p...

Nov 22, 2025
CVE-2025-66114
5.3

This vulnerability allows unauthorized users to access WooCommerce product variation data due to missing authorization checks in the 'Show Variations ...

Nov 21, 2025
CVE-2025-66107
5.3

This CVE describes a Missing Authorization vulnerability in the Subscriptions & Memberships for PayPal WordPress plugin that allows attackers to bypas...

Nov 21, 2025
CVE-2025-66109
5.3

This CVE describes a missing authorization vulnerability in the Cart Weight for WooCommerce plugin that allows attackers to bypass access controls. It...

Nov 21, 2025
CVE-2025-66110
5.3

This CVE describes a Missing Authorization vulnerability in the bPlugins Tiktok Feed WordPress plugin (b-tiktok-feed) that allows attackers to exploit...

Nov 21, 2025
CVE-2025-66099
5.3

This CVE describes a missing authorization vulnerability in the ThemeAtelier Chat Help WordPress plugin that allows attackers to bypass access control...

Nov 21, 2025
CVE-2025-66086
5.3

This CVE describes a Missing Authorization vulnerability in the Cozy Vision SMS Alert Order Notifications WordPress plugin that allows attackers to by...

Nov 21, 2025
CVE-2025-66087
5.3

This CVE describes a missing authorization vulnerability in the PropertyHive WordPress plugin that allows attackers to bypass access controls. It affe...

Nov 21, 2025
CVE-2025-66071
5.3

This CVE describes a Missing Authorization vulnerability in the Custom Order Numbers for WooCommerce WordPress plugin that allows unauthorized users t...

Nov 21, 2025
CVE-2025-66065
5.3

This CVE describes a missing authorization vulnerability in the Gutenverse WordPress plugin that allows attackers to bypass access controls. It affect...

Nov 21, 2025
CVE-2025-66060
5.3

This CVE describes a missing authorization vulnerability in the Seriously Simple Podcasting WordPress plugin that allows attackers to bypass access co...

Nov 21, 2025
CVE-2025-10054
5.3

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to remove...

Nov 21, 2025
CVE-2025-12170
5.3

The Checkbox plugin for WordPress has an unauthenticated AJAX endpoint that allows attackers to clear log files without proper authorization. This aff...

Nov 21, 2025
CVE-2025-12778
5.3

This vulnerability allows unauthenticated attackers to extract partial metadata of all WordPress users, including first names, last names, and email a...

Nov 20, 2025
CVE-2025-12391
5.3

The Restrictions for BuddyPress WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify user track...

Nov 18, 2025
CVE-2025-12392
5.3

The Cryptocurrency Payment Gateway for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to...

Nov 18, 2025
CVE-2025-12849
5.3

The Contest Gallery WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to inject arbitrary media attachm...

Nov 15, 2025
CVE-2025-64277
5.3

This CVE describes a Missing Authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....

Nov 13, 2025
CVE-2025-64370
5.3

This CVE describes a missing authorization vulnerability in the YOP Poll WordPress plugin that allows attackers to exploit incorrectly configured acce...

Nov 13, 2025
CVE-2025-12891
5.3

The Survey Maker WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to view all survey submissions. Thi...

Nov 13, 2025
CVE-2025-12892
5.3

The Survey Maker WordPress plugin allows unauthenticated attackers to modify the ays_survey_maker_upgrade_plugin option due to missing capability chec...

Nov 13, 2025
CVE-2025-12979
5.3

The Welcart e-Commerce plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive payme...

Nov 13, 2025
CVE-2025-33185
5.3

NVIDIA AIStore has an authentication vulnerability (CWE-862: Missing Authorization) that allows unauthenticated attackers to access sensitive informat...

Nov 11, 2025
CVE-2025-11996
5.3

The Find Unused Images WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete all image attachment...

Nov 11, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,051 CVEs classified as CWE-862, with 228 rated critical and 857 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free