CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,058
Total CVEs
228
Critical
864
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 124
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 18
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,058)

CVE-2025-58969
5.3

This CVE describes a missing authorization vulnerability in the WordPress Custom Login URL plugin that allows attackers to bypass intended access cont...

Sep 22, 2025
CVE-2025-58685
5.3

This CVE describes a Missing Authorization vulnerability in the Cecabank WooCommerce Plugin for WordPress. It allows attackers to exploit incorrectly ...

Sep 22, 2025
CVE-2025-58679
5.3

This CVE describes a Missing Authorization vulnerability in the AppMySite WordPress plugin that allows attackers to bypass access controls. It affects...

Sep 22, 2025
CVE-2025-58681
5.3

This CVE describes a Missing Authorization vulnerability in the Easy Quotes WordPress plugin that allows attackers to bypass intended access controls....

Sep 22, 2025
CVE-2025-58247
5.3

This CVE describes a missing authorization vulnerability in the TI WooCommerce Wishlist WordPress plugin that allows attackers to bypass access contro...

Sep 22, 2025
CVE-2025-58222
5.3

This CVE describes a missing authorization vulnerability in the Maidul Team Manager WordPress plugin that allows attackers to bypass access controls. ...

Sep 22, 2025
CVE-2025-58029
5.3

This CVE describes a missing authorization vulnerability in the Classic Widgets with Block-based Widgets WordPress plugin that allows attackers to acc...

Sep 22, 2025
CVE-2025-58000
5.3

This CVE describes a missing authorization vulnerability in the Memberful WordPress plugin that allows attackers to access functionality not properly ...

Sep 22, 2025
CVE-2025-58003
5.3

This CVE describes a missing authorization vulnerability in the Javo Core WordPress plugin that allows attackers to bypass access controls and perform...

Sep 22, 2025
CVE-2025-58004
5.3

This CVE describes a missing authorization vulnerability in the DriCub WordPress theme that allows attackers to bypass access controls. It affects all...

Sep 22, 2025
CVE-2025-57987
5.3

This CVE describes a missing authorization vulnerability in the ThimPress WP Events Manager WordPress plugin that allows attackers to bypass intended ...

Sep 22, 2025
CVE-2025-57976
5.3

This CVE describes a missing authorization vulnerability in the CardCom Payment Gateway WordPress plugin that allows attackers to bypass access contro...

Sep 22, 2025
CVE-2025-57971
5.3

This CVE describes a Missing Authorization vulnerability in SALESmanago & Leadoo WordPress plugins that allows attackers to bypass access controls. It...

Sep 22, 2025
CVE-2025-57957
5.3

This CVE describes a missing authorization vulnerability in the wpcraft WooMS WordPress plugin that allows attackers to bypass intended access control...

Sep 22, 2025
CVE-2025-57958
5.3

This CVE describes a missing authorization vulnerability in the WPXPO WowAddons WordPress plugin that allows attackers to bypass intended access contr...

Sep 22, 2025
CVE-2025-57944
5.3

This CVE describes a missing authorization vulnerability in the Skimlinks Affiliate Marketing Tool WordPress plugin that allows attackers to access fu...

Sep 22, 2025
CVE-2025-57939
5.3

This CVE describes a missing authorization vulnerability in the Image Hover Effects - Elementor Addon WordPress plugin. Attackers can exploit incorrec...

Sep 22, 2025
CVE-2025-57921
5.3

This CVE describes a missing authorization vulnerability in the N-Media Frontend File Manager WordPress plugin that allows attackers to bypass access ...

Sep 22, 2025
CVE-2025-57907
5.3

This CVE describes a Missing Authorization vulnerability in the Heureka WordPress plugin that allows attackers to access functionality not properly re...

Sep 22, 2025
CVE-2025-57899
5.3

This CVE describes a missing authorization vulnerability in the WP Compress WordPress plugin that allows attackers to access functionality not properl...

Sep 22, 2025
CVE-2025-10305
5.3

The Secure Passkeys WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view...

Sep 20, 2025
CVE-2025-59474
5.3

This vulnerability allows attackers without Overall/Read permission in Jenkins to list agent names through the sidepanel executors widget. It affects ...

Sep 17, 2025
CVE-2025-8999
5.3

The Sydney WordPress theme has a missing capability check in the 'activate_modules' function, allowing authenticated users with Subscriber-level acces...

Sep 17, 2025
CVE-2025-43805
5.3

This vulnerability allows remote attackers to view display page templates in Liferay Portal/DXP without proper authorization checks. Attackers can exp...

Sep 16, 2025
CVE-2025-8492
5.3

The Salon Booking System WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to execute AJAX actions, inc...

Sep 11, 2025
CVE-2025-58980
5.3

This CVE describes a missing authorization vulnerability in the Export WP Page to Static HTML/CSS WordPress plugin that allows attackers to access fun...

Sep 9, 2025
CVE-2025-58978
5.3

This vulnerability allows attackers to bypass authorization controls in the WP Swings PDF Generator for WordPress plugin, potentially accessing restri...

Sep 9, 2025
CVE-2025-58979
5.3

CVE-2025-58979 is a missing authorization vulnerability in the BerqWP WordPress plugin that allows attackers to bypass access controls and potentially...

Sep 9, 2025
CVE-2025-53348
5.3

This CVE describes a missing authorization vulnerability in the Kalium WordPress theme that allows unauthorized users to access functionality intended...

Sep 9, 2025
CVE-2025-49860
5.3

This CVE describes a Missing Authorization vulnerability in the Majestic Support WordPress plugin that allows unauthorized users to access functionali...

Sep 9, 2025
CVE-2025-58634
5.3

This CVE describes a missing authorization vulnerability in the PeachPay Payments WordPress plugin that allows attackers to bypass access controls. It...

Sep 3, 2025
CVE-2025-58635
5.3

This CVE describes a missing authorization vulnerability in the Support Genix WordPress plugin that allows attackers to bypass intended access control...

Sep 3, 2025
CVE-2025-58613
5.3

This CVE describes a missing authorization vulnerability in the Barn2 Plugins Posts Table with Search & Sort WordPress plugin. It allows attackers to ...

Sep 3, 2025
CVE-2025-58600
5.3

This CVE describes a missing authorization vulnerability in the Paid Member Subscriptions WordPress plugin that allows attackers to bypass access cont...

Sep 3, 2025
CVE-2025-58603
5.3

This CVE describes a missing authorization vulnerability in the Surfer SEO WordPress plugin that allows attackers to bypass access controls. It affect...

Sep 3, 2025
CVE-2025-58201
5.3

This CVE describes a Missing Authorization vulnerability in the AfterShip Tracking WordPress plugin that allows unauthorized users to access functiona...

Aug 27, 2025
CVE-2025-7821
5.3

The WC Plus WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify the site's favicon logo base. ...

Aug 23, 2025
CVE-2025-57896
5.3

This CVE describes a Missing Authorization vulnerability in the Church Admin WordPress plugin that allows attackers to bypass access controls and perf...

Aug 22, 2025
CVE-2025-49406
5.3

This CVE describes a missing authorization vulnerability in the Houzez WordPress theme that allows attackers to access functionality not properly cons...

Aug 20, 2025
CVE-2025-54739
5.3

This CVE describes a missing authorization vulnerability in POSIMYTH Nexter Blocks WordPress plugin that allows attackers to bypass intended access co...

Aug 14, 2025
CVE-2025-54730
5.3

This CVE describes a missing authorization vulnerability in the PARETO Digital Embedder for Google Reviews WordPress plugin. It allows attackers to ac...

Aug 14, 2025
CVE-2025-51308
5.3

In Gatling Enterprise versions below 1.25.0, low-privileged users without admin roles can access read-only REST API endpoints due to missing authoriza...

Aug 6, 2025
CVE-2025-4370
5.3

The Brizy Page Builder WordPress plugin has an unauthenticated file upload vulnerability that allows attackers to upload .TXT files to the server. Thi...

Jul 29, 2025
CVE-2025-6215
5.3

The Omnishop WordPress plugin has an unauthenticated registration bypass vulnerability that allows attackers to create arbitrary customer accounts eve...

Jul 23, 2025
CVE-2025-6720
5.3

The Vchasno Kasa WordPress plugin has an unauthenticated data deletion vulnerability that allows attackers to clear log files without authentication. ...

Jul 19, 2025
CVE-2025-5811
5.3

The Listly WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to delete arbitrary transient values stor...

Jul 18, 2025
CVE-2025-53986
5.3

This CVE describes a missing authorization vulnerability in the Hestia WordPress theme that allows attackers to access functionality not properly rest...

Jul 16, 2025
CVE-2025-30929
5.3

This CVE describes a Missing Authorization vulnerability in the amazewp fluXtore WordPress plugin that allows attackers to exploit incorrectly configu...

Jul 4, 2025
CVE-2025-53295
5.3

CVE-2025-53295 is a missing authorization vulnerability in the iCount Payment Gateway WordPress plugin that allows attackers to access functionality n...

Jun 27, 2025
CVE-2025-5813
5.3

The Amazon Products to WooCommerce WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create new pro...

Jun 26, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,058 CVEs classified as CWE-862, with 228 rated critical and 864 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free