CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,058)
This CVE describes a missing authorization vulnerability in the WordPress Custom Login URL plugin that allows attackers to bypass intended access cont...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in the Cecabank WooCommerce Plugin for WordPress. It allows attackers to exploit incorrectly ...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in the AppMySite WordPress plugin that allows attackers to bypass access controls. It affects...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in the Easy Quotes WordPress plugin that allows attackers to bypass intended access controls....
Sep 22, 2025This CVE describes a missing authorization vulnerability in the TI WooCommerce Wishlist WordPress plugin that allows attackers to bypass access contro...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Maidul Team Manager WordPress plugin that allows attackers to bypass access controls. ...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Classic Widgets with Block-based Widgets WordPress plugin that allows attackers to acc...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Memberful WordPress plugin that allows attackers to access functionality not properly ...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Javo Core WordPress plugin that allows attackers to bypass access controls and perform...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the DriCub WordPress theme that allows attackers to bypass access controls. It affects all...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the ThimPress WP Events Manager WordPress plugin that allows attackers to bypass intended ...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the CardCom Payment Gateway WordPress plugin that allows attackers to bypass access contro...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in SALESmanago & Leadoo WordPress plugins that allows attackers to bypass access controls. It...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the wpcraft WooMS WordPress plugin that allows attackers to bypass intended access control...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the WPXPO WowAddons WordPress plugin that allows attackers to bypass intended access contr...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Skimlinks Affiliate Marketing Tool WordPress plugin that allows attackers to access fu...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the Image Hover Effects - Elementor Addon WordPress plugin. Attackers can exploit incorrec...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the N-Media Frontend File Manager WordPress plugin that allows attackers to bypass access ...
Sep 22, 2025This CVE describes a Missing Authorization vulnerability in the Heureka WordPress plugin that allows attackers to access functionality not properly re...
Sep 22, 2025This CVE describes a missing authorization vulnerability in the WP Compress WordPress plugin that allows attackers to access functionality not properl...
Sep 22, 2025The Secure Passkeys WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view...
Sep 20, 2025This vulnerability allows attackers without Overall/Read permission in Jenkins to list agent names through the sidepanel executors widget. It affects ...
Sep 17, 2025The Sydney WordPress theme has a missing capability check in the 'activate_modules' function, allowing authenticated users with Subscriber-level acces...
Sep 17, 2025This vulnerability allows remote attackers to view display page templates in Liferay Portal/DXP without proper authorization checks. Attackers can exp...
Sep 16, 2025The Salon Booking System WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to execute AJAX actions, inc...
Sep 11, 2025This CVE describes a missing authorization vulnerability in the Export WP Page to Static HTML/CSS WordPress plugin that allows attackers to access fun...
Sep 9, 2025This vulnerability allows attackers to bypass authorization controls in the WP Swings PDF Generator for WordPress plugin, potentially accessing restri...
Sep 9, 2025CVE-2025-58979 is a missing authorization vulnerability in the BerqWP WordPress plugin that allows attackers to bypass access controls and potentially...
Sep 9, 2025This CVE describes a missing authorization vulnerability in the Kalium WordPress theme that allows unauthorized users to access functionality intended...
Sep 9, 2025This CVE describes a Missing Authorization vulnerability in the Majestic Support WordPress plugin that allows unauthorized users to access functionali...
Sep 9, 2025This CVE describes a missing authorization vulnerability in the PeachPay Payments WordPress plugin that allows attackers to bypass access controls. It...
Sep 3, 2025This CVE describes a missing authorization vulnerability in the Support Genix WordPress plugin that allows attackers to bypass intended access control...
Sep 3, 2025This CVE describes a missing authorization vulnerability in the Barn2 Plugins Posts Table with Search & Sort WordPress plugin. It allows attackers to ...
Sep 3, 2025This CVE describes a missing authorization vulnerability in the Paid Member Subscriptions WordPress plugin that allows attackers to bypass access cont...
Sep 3, 2025This CVE describes a missing authorization vulnerability in the Surfer SEO WordPress plugin that allows attackers to bypass access controls. It affect...
Sep 3, 2025This CVE describes a Missing Authorization vulnerability in the AfterShip Tracking WordPress plugin that allows unauthorized users to access functiona...
Aug 27, 2025The WC Plus WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify the site's favicon logo base. ...
Aug 23, 2025This CVE describes a Missing Authorization vulnerability in the Church Admin WordPress plugin that allows attackers to bypass access controls and perf...
Aug 22, 2025This CVE describes a missing authorization vulnerability in the Houzez WordPress theme that allows attackers to access functionality not properly cons...
Aug 20, 2025This CVE describes a missing authorization vulnerability in POSIMYTH Nexter Blocks WordPress plugin that allows attackers to bypass intended access co...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the PARETO Digital Embedder for Google Reviews WordPress plugin. It allows attackers to ac...
Aug 14, 2025In Gatling Enterprise versions below 1.25.0, low-privileged users without admin roles can access read-only REST API endpoints due to missing authoriza...
Aug 6, 2025The Brizy Page Builder WordPress plugin has an unauthenticated file upload vulnerability that allows attackers to upload .TXT files to the server. Thi...
Jul 29, 2025The Omnishop WordPress plugin has an unauthenticated registration bypass vulnerability that allows attackers to create arbitrary customer accounts eve...
Jul 23, 2025The Vchasno Kasa WordPress plugin has an unauthenticated data deletion vulnerability that allows attackers to clear log files without authentication. ...
Jul 19, 2025The Listly WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary transient values stor...
Jul 18, 2025This CVE describes a missing authorization vulnerability in the Hestia WordPress theme that allows attackers to access functionality not properly rest...
Jul 16, 2025This CVE describes a Missing Authorization vulnerability in the amazewp fluXtore WordPress plugin that allows attackers to exploit incorrectly configu...
Jul 4, 2025CVE-2025-53295 is a missing authorization vulnerability in the iCount Payment Gateway WordPress plugin that allows attackers to access functionality n...
Jun 27, 2025The Amazon Products to WooCommerce WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create new pro...
Jun 26, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,058 CVEs classified as CWE-862, with 228 rated critical and 864 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free