CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,061
Total CVEs
228
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,061)

CVE-2025-30929
5.3

This CVE describes a Missing Authorization vulnerability in the amazewp fluXtore WordPress plugin that allows attackers to exploit incorrectly configu...

Jul 4, 2025
CVE-2025-53295
5.3

CVE-2025-53295 is a missing authorization vulnerability in the iCount Payment Gateway WordPress plugin that allows attackers to access functionality n...

Jun 27, 2025
CVE-2025-5813
5.3

The Amazon Products to WooCommerce WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create new pro...

Jun 26, 2025
CVE-2025-49990
5.3

This CVE describes a missing authorization vulnerability in the ContentStudio WordPress plugin that allows attackers to access functionality not prope...

Jun 20, 2025
CVE-2025-49993
5.3

This CVE describes a Missing Authorization vulnerability in the Cookie-Script.com WordPress plugin that allows attackers to bypass access controls. It...

Jun 20, 2025
CVE-2025-49996
5.3

This CVE describes a missing authorization vulnerability in the WP Visitor Statistics WordPress plugin that allows attackers to access functionality n...

Jun 20, 2025
CVE-2025-49986
5.3

This CVE describes a missing authorization vulnerability in the Video List Manager WordPress plugin that allows attackers to access functionality not ...

Jun 20, 2025
CVE-2025-49988
5.3

This vulnerability allows attackers to bypass authorization controls in the Renzo Contact Form 7 AWeber Extension WordPress plugin. Attackers can expl...

Jun 20, 2025
CVE-2025-48444
5.3

This CVE describes a Missing Authorization vulnerability in Drupal's Quick Node Block module that allows attackers to perform forceful browsing to acc...

Jun 11, 2025
CVE-2025-49509
5.3

This CVE describes a Missing Authorization vulnerability in the Roland Beaussant Audio Editor & Recorder WordPress plugin. It allows attackers to bypa...

Jun 10, 2025
CVE-2025-49268
5.3

This CVE describes a missing authorization vulnerability in Soft8Soft LLC's Verge3D plugin for WordPress. It allows attackers to bypass access control...

Jun 6, 2025
CVE-2025-49270
5.3

This vulnerability allows unauthorized users to access functionality that should be restricted by access controls in the WP-CRM System WordPress plugi...

Jun 6, 2025
CVE-2025-49241
5.3

This CVE describes a Missing Authorization vulnerability in the oik WordPress plugin that allows attackers to bypass access controls. It affects all v...

Jun 6, 2025
CVE-2025-30945
5.3

This CVE describes a missing authorization vulnerability in the Taskbuilder WordPress plugin that allows attackers to access functionality not properl...

Jun 6, 2025
CVE-2025-30934
5.3

This CVE describes a Missing Authorization vulnerability in the OLIVESYSTEM Diagnosis Generator WordPress plugin that allows attackers to access funct...

Jun 6, 2025
CVE-2025-29006
5.3

This CVE describes a missing authorization vulnerability in the Direct Checkout for WooCommerce Lite plugin that allows attackers to access functional...

Jun 6, 2025
CVE-2025-23971
5.3

CVE-2025-23971 is a missing authorization vulnerability in the KI Live Video Conferences WordPress plugin that allows attackers to bypass access contr...

Jun 6, 2025
CVE-2025-24763
5.3

This CVE describes a Missing Authorization vulnerability in the bbPress API WordPress plugin that allows attackers to bypass intended access controls....

Jun 6, 2025
CVE-2025-48337
5.3

This CVE describes a Missing Authorization vulnerability in the QuickCab WordPress plugin that allows unauthorized users to access functionality inten...

Jun 6, 2025
CVE-2025-2506
5.3

This vulnerability allows users with only CONNECT permissions to a database configured for replication to execute pglogical commands and gain unauthor...

May 22, 2025
CVE-2025-47942
5.3

The Open edX Platform allows unauthorized users to download python_lib.zip files from courses, which may contain custom grading code or answers to cou...

May 21, 2025
CVE-2025-39460
5.3

This CVE describes a missing authorization vulnerability in the Eduma WordPress theme that allows attackers to bypass access controls and perform unau...

May 19, 2025
CVE-2025-39373
5.3

This CVE describes a Missing Authorization vulnerability in the JNews WordPress theme that allows unauthorized users to access functionality intended ...

May 19, 2025
CVE-2025-39353
5.3

This CVE describes a missing authorization vulnerability in the Grand Restaurant WordPress theme that allows attackers to bypass access controls. Atta...

May 19, 2025
CVE-2025-48282
5.3

This CVE describes a Missing Authorization vulnerability in the Majestic Support WordPress plugin that allows attackers to exploit incorrectly configu...

May 19, 2025
CVE-2025-48116
5.3

This CVE describes a missing authorization vulnerability in the EventON WordPress plugin that allows attackers to access functionality not properly co...

May 16, 2025
CVE-2025-47564
5.3

This CVE describes a missing authorization vulnerability in the EventON WordPress plugin that allows attackers to access functionality not properly re...

May 16, 2025
CVE-2025-32296
5.3

This CVE describes a missing authorization vulnerability in the quantumcloud Simple Link Directory Pro WordPress plugin that allows attackers to bypas...

May 16, 2025
CVE-2025-31071
5.3

This CVE describes a missing authorization vulnerability in the HotStar WordPress theme that allows attackers to bypass access controls. It affects al...

May 16, 2025
CVE-2025-31066
5.3

This CVE describes a missing authorization vulnerability in the Acerola WordPress theme that allows attackers to bypass access controls. It affects al...

May 16, 2025
CVE-2024-56006
5.3

This CVE describes a missing authorization vulnerability in the Jetpack Debug Tools WordPress plugin that allows unauthorized users to access debug fu...

May 15, 2025
CVE-2025-43004
5.3

CVE-2025-43004 is a security misconfiguration vulnerability in SAP systems that allows unauthenticated users to access Production Operator Dashboards ...

May 13, 2025
CVE-2025-47688
5.3

This CVE describes a missing authorization vulnerability in the Advanced File Manager WordPress plugin that allows attackers to exploit incorrectly co...

May 7, 2025
CVE-2025-47486
5.3

This CVE describes a Missing Authorization vulnerability in the CyberChimps Gutenberg & Elementor Templates Importer For Responsive WordPress plugin. ...

May 7, 2025
CVE-2025-47457
5.3

This CVE describes a missing authorization vulnerability in the LocateAndFilter WordPress plugin that allows attackers to access functionality not pro...

May 7, 2025
CVE-2025-39367
5.3

This CVE describes a Missing Authorization vulnerability in the Kleo WordPress theme that allows unauthorized users to access functionality intended o...

Apr 28, 2025
CVE-2025-3912
5.3

This vulnerability allows unauthenticated attackers to read sensitive configuration data from the WS Form LITE WordPress plugin, including API keys fo...

Apr 25, 2025
CVE-2025-46489
5.3

This CVE describes a missing authorization vulnerability in the Bulk Assign Linked Products For WooCommerce WordPress plugin. It allows unauthorized u...

Apr 24, 2025
CVE-2025-46247
5.3

This CVE describes a missing authorization vulnerability in the Appointment Booking Calendar WordPress plugin that allows attackers to access function...

Apr 22, 2025
CVE-2025-39457
5.3

This CVE describes a missing authorization vulnerability in the Booking and Rental Manager WordPress plugin that allows attackers to bypass access con...

Apr 17, 2025
CVE-2025-32259
5.3

CVE-2025-32259 is a missing authorization vulnerability in the WP ULike WordPress plugin that allows unauthenticated users to spoof content by manipul...

Apr 10, 2025
CVE-2025-31042
5.3

This CVE describes a Missing Authorization vulnerability in the Sandwich Adsense WordPress plugin that allows attackers to bypass access controls. It ...

Apr 9, 2025
CVE-2025-31012
5.3

This CVE describes a missing authorization vulnerability in the Age Gate WordPress plugin that allows attackers to bypass access controls and access f...

Apr 9, 2025
CVE-2025-2568
5.3

The Vayu Blocks WordPress plugin has missing capability checks in two callback functions, allowing unauthenticated attackers to read plugin options an...

Apr 8, 2025
CVE-2025-32258
5.3

This CVE describes a missing authorization vulnerability in the Simple Website Logo WordPress plugin that allows attackers to bypass access controls. ...

Apr 4, 2025
CVE-2025-32256
5.3

CVE-2025-32256 is a missing authorization vulnerability in SurveyJS that allows attackers to access functionality not properly constrained by access c...

Apr 4, 2025
CVE-2025-32252
5.3

This CVE describes a missing authorization vulnerability in the WP Genealogy WordPress plugin that allows attackers to bypass access controls. It affe...

Apr 4, 2025
CVE-2025-32254
5.3

This CVE describes a missing authorization vulnerability in the WPBookit WordPress plugin that allows attackers to access functionality not properly c...

Apr 4, 2025
CVE-2025-32225
5.3

This CVE describes a missing authorization vulnerability in the WP Event Manager WordPress plugin that allows attackers to bypass intended access cont...

Apr 4, 2025
CVE-2025-31628
5.3

This CVE describes a Missing Authorization vulnerability in the Sliced Invoices WordPress plugin that allows unauthorized users to access functionalit...

Apr 1, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free