CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,061)
This CVE describes a Missing Authorization vulnerability in the amazewp fluXtore WordPress plugin that allows attackers to exploit incorrectly configu...
Jul 4, 2025CVE-2025-53295 is a missing authorization vulnerability in the iCount Payment Gateway WordPress plugin that allows attackers to access functionality n...
Jun 27, 2025The Amazon Products to WooCommerce WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create new pro...
Jun 26, 2025This CVE describes a missing authorization vulnerability in the ContentStudio WordPress plugin that allows attackers to access functionality not prope...
Jun 20, 2025This CVE describes a Missing Authorization vulnerability in the Cookie-Script.com WordPress plugin that allows attackers to bypass access controls. It...
Jun 20, 2025This CVE describes a missing authorization vulnerability in the WP Visitor Statistics WordPress plugin that allows attackers to access functionality n...
Jun 20, 2025This CVE describes a missing authorization vulnerability in the Video List Manager WordPress plugin that allows attackers to access functionality not ...
Jun 20, 2025This vulnerability allows attackers to bypass authorization controls in the Renzo Contact Form 7 AWeber Extension WordPress plugin. Attackers can expl...
Jun 20, 2025This CVE describes a Missing Authorization vulnerability in Drupal's Quick Node Block module that allows attackers to perform forceful browsing to acc...
Jun 11, 2025This CVE describes a Missing Authorization vulnerability in the Roland Beaussant Audio Editor & Recorder WordPress plugin. It allows attackers to bypa...
Jun 10, 2025This CVE describes a missing authorization vulnerability in Soft8Soft LLC's Verge3D plugin for WordPress. It allows attackers to bypass access control...
Jun 6, 2025This vulnerability allows unauthorized users to access functionality that should be restricted by access controls in the WP-CRM System WordPress plugi...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the oik WordPress plugin that allows attackers to bypass access controls. It affects all v...
Jun 6, 2025This CVE describes a missing authorization vulnerability in the Taskbuilder WordPress plugin that allows attackers to access functionality not properl...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the OLIVESYSTEM Diagnosis Generator WordPress plugin that allows attackers to access funct...
Jun 6, 2025This CVE describes a missing authorization vulnerability in the Direct Checkout for WooCommerce Lite plugin that allows attackers to access functional...
Jun 6, 2025CVE-2025-23971 is a missing authorization vulnerability in the KI Live Video Conferences WordPress plugin that allows attackers to bypass access contr...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the bbPress API WordPress plugin that allows attackers to bypass intended access controls....
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the QuickCab WordPress plugin that allows unauthorized users to access functionality inten...
Jun 6, 2025This vulnerability allows users with only CONNECT permissions to a database configured for replication to execute pglogical commands and gain unauthor...
May 22, 2025The Open edX Platform allows unauthorized users to download python_lib.zip files from courses, which may contain custom grading code or answers to cou...
May 21, 2025This CVE describes a missing authorization vulnerability in the Eduma WordPress theme that allows attackers to bypass access controls and perform unau...
May 19, 2025This CVE describes a Missing Authorization vulnerability in the JNews WordPress theme that allows unauthorized users to access functionality intended ...
May 19, 2025This CVE describes a missing authorization vulnerability in the Grand Restaurant WordPress theme that allows attackers to bypass access controls. Atta...
May 19, 2025This CVE describes a Missing Authorization vulnerability in the Majestic Support WordPress plugin that allows attackers to exploit incorrectly configu...
May 19, 2025This CVE describes a missing authorization vulnerability in the EventON WordPress plugin that allows attackers to access functionality not properly co...
May 16, 2025This CVE describes a missing authorization vulnerability in the EventON WordPress plugin that allows attackers to access functionality not properly re...
May 16, 2025This CVE describes a missing authorization vulnerability in the quantumcloud Simple Link Directory Pro WordPress plugin that allows attackers to bypas...
May 16, 2025This CVE describes a missing authorization vulnerability in the HotStar WordPress theme that allows attackers to bypass access controls. It affects al...
May 16, 2025This CVE describes a missing authorization vulnerability in the Acerola WordPress theme that allows attackers to bypass access controls. It affects al...
May 16, 2025This CVE describes a missing authorization vulnerability in the Jetpack Debug Tools WordPress plugin that allows unauthorized users to access debug fu...
May 15, 2025CVE-2025-43004 is a security misconfiguration vulnerability in SAP systems that allows unauthenticated users to access Production Operator Dashboards ...
May 13, 2025This CVE describes a missing authorization vulnerability in the Advanced File Manager WordPress plugin that allows attackers to exploit incorrectly co...
May 7, 2025This CVE describes a Missing Authorization vulnerability in the CyberChimps Gutenberg & Elementor Templates Importer For Responsive WordPress plugin. ...
May 7, 2025This CVE describes a missing authorization vulnerability in the LocateAndFilter WordPress plugin that allows attackers to access functionality not pro...
May 7, 2025This CVE describes a Missing Authorization vulnerability in the Kleo WordPress theme that allows unauthorized users to access functionality intended o...
Apr 28, 2025This vulnerability allows unauthenticated attackers to read sensitive configuration data from the WS Form LITE WordPress plugin, including API keys fo...
Apr 25, 2025This CVE describes a missing authorization vulnerability in the Bulk Assign Linked Products For WooCommerce WordPress plugin. It allows unauthorized u...
Apr 24, 2025This CVE describes a missing authorization vulnerability in the Appointment Booking Calendar WordPress plugin that allows attackers to access function...
Apr 22, 2025This CVE describes a missing authorization vulnerability in the Booking and Rental Manager WordPress plugin that allows attackers to bypass access con...
Apr 17, 2025CVE-2025-32259 is a missing authorization vulnerability in the WP ULike WordPress plugin that allows unauthenticated users to spoof content by manipul...
Apr 10, 2025This CVE describes a Missing Authorization vulnerability in the Sandwich Adsense WordPress plugin that allows attackers to bypass access controls. It ...
Apr 9, 2025This CVE describes a missing authorization vulnerability in the Age Gate WordPress plugin that allows attackers to bypass access controls and access f...
Apr 9, 2025The Vayu Blocks WordPress plugin has missing capability checks in two callback functions, allowing unauthenticated attackers to read plugin options an...
Apr 8, 2025This CVE describes a missing authorization vulnerability in the Simple Website Logo WordPress plugin that allows attackers to bypass access controls. ...
Apr 4, 2025CVE-2025-32256 is a missing authorization vulnerability in SurveyJS that allows attackers to access functionality not properly constrained by access c...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the WP Genealogy WordPress plugin that allows attackers to bypass access controls. It affe...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the WPBookit WordPress plugin that allows attackers to access functionality not properly c...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the WP Event Manager WordPress plugin that allows attackers to bypass intended access cont...
Apr 4, 2025This CVE describes a Missing Authorization vulnerability in the Sliced Invoices WordPress plugin that allows unauthorized users to access functionalit...
Apr 1, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free