CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,061)
This CVE describes a missing authorization vulnerability in the Agency Toolkit WordPress plugin that allows attackers to bypass intended access contro...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the WordPress Adverts Plugin that allows attackers to bypass access controls and perform u...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the WordPress Question Answer plugin that allows attackers to access functionality not pro...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Simple Icons plugin that allows attackers to bypass access controls. It affe...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in WebProtect.ai Astra Security Suite WordPress plugin that allows attackers to bypass access...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the GDPR Cookie Notice WordPress plugin that allows attackers to exploit incorrectly confi...
Apr 1, 2025This vulnerability allows attackers to bypass authorization controls in the Jaap Jansma Connector to CiviCRM with CiviMcRestFace WordPress plugin. Att...
Mar 31, 2025This CVE describes a Missing Authorization vulnerability in Simple:Press WordPress plugin that allows attackers to bypass access controls and perform ...
Mar 31, 2025This CVE describes a missing authorization vulnerability in the LearnPress WordPress plugin that allows attackers to bypass access controls. It affect...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the iNET Webkit WordPress plugin that allows attackers to access functionality not properl...
Mar 27, 2025This CVE describes a Missing Authorization vulnerability in the WpEvently WordPress plugin that allows attackers to bypass access controls. Attackers ...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the Taxi Booking Manager for WooCommerce WordPress plugin. Attackers can exploit incorrect...
Mar 27, 2025This CVE describes a Missing Authorization vulnerability in the Hossni Mubarak Cool Author Box WordPress plugin that allows attackers to exploit incor...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the SNORDIAN's H5PxAPIkatchu WordPress plugin that allows attackers to access functionalit...
Mar 27, 2025This CVE describes a Missing Authorization vulnerability in the Music Press Pro WordPress plugin that allows attackers to bypass access controls. It a...
Mar 24, 2025This CVE describes a missing authorization vulnerability in the PluginOps Top Bar WordPress plugin that allows attackers to bypass access controls. It...
Mar 24, 2025The LifterLMS WordPress plugin has an unauthenticated post trashing vulnerability that allows attackers without credentials to move all published post...
Mar 19, 2025This vulnerability in the ShareThis Dashboard for Google Analytics WordPress plugin allows unauthenticated attackers to disable all plugin features by...
Mar 14, 2025This vulnerability in the Resido WordPress theme allows unauthenticated attackers to delete or save API keys without proper authorization checks. Any ...
Mar 14, 2025The WP Crowdfunding WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to down...
Mar 12, 2025This CVE describes a missing authorization vulnerability in the WordPress plugin Block Spam By Math Reloaded that allows attackers to access functiona...
Mar 11, 2025This vulnerability in the School Management System for WordPress plugin allows unauthenticated attackers to delete arbitrary posts due to missing capa...
Mar 7, 2025This vulnerability allows unauthenticated attackers to register user accounts on WordPress sites using the JNews theme, even when user registration is...
Mar 5, 2025The IP2Location Redirection plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to download the plug...
Mar 1, 2025This CVE describes a missing authorization vulnerability in the Pixelite Events Manager WordPress plugin that allows attackers to exploit incorrectly ...
Feb 26, 2025This vulnerability in the Event Tickets and Registration WordPress plugin allows authenticated attackers with Contributor-level access or higher to de...
Feb 21, 2025The LTL Freight Quotes – GlobalTranz Edition WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to mo...
Feb 20, 2025This vulnerability allows unauthenticated attackers to modify gift voucher values, expiration dates, and user notes in WordPress sites using the Gift ...
Feb 20, 2025The Raptive Ads WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to reset ad and cls files. This affec...
Feb 19, 2025The WordPress Portfolio Builder plugin has an authorization bypass vulnerability that allows unauthenticated attackers to add arbitrary videos to any ...
Feb 19, 2025The PeproDev Ultimate Invoice WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to view inv...
Feb 19, 2025The WP Extended WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to reorder posts. This affects all Wo...
Feb 12, 2025This vulnerability allows unauthenticated attackers to generate technical metadata in SAP systems via an RFC-enabled function module in transaction SD...
Feb 11, 2025This vulnerability in the WordPress Contact Forms by Cimatti plugin allows unauthenticated attackers to download form submissions containing potential...
Feb 1, 2025This CVE describes a missing authorization vulnerability in LearnDash LMS WordPress plugin that allows attackers to bypass access controls and access ...
Jan 27, 2025CVE-2025-24600 is a missing authorization vulnerability in the RSVPMaker WordPress plugin that allows unauthorized users to access restricted function...
Jan 27, 2025This vulnerability allows unauthorized users to access sensitive data in WooCommerce Quick View plugin due to missing authorization checks. It affects...
Jan 24, 2025This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers with network access via HTTP to read sensitive data. It a...
Jan 21, 2025The Atarim WordPress plugin has a vulnerability that allows unauthenticated attackers to delete project pages and files without proper authorization. ...
Jan 21, 2025This vulnerability in the Evergreen Content Poster WordPress plugin allows unauthenticated attackers to delete arbitrary posts and pages due to missin...
Jan 18, 2025This vulnerability allows attackers to bypass authorization controls in the Contact Form 7 Anti Spambot WordPress plugin, potentially accessing admini...
Jan 16, 2025This CVE describes a Missing Authorization vulnerability in the Sanjaysolutions Loginplus WordPress plugin that allows attackers to access functionali...
Jan 16, 2025This CVE describes a Missing Authorization vulnerability in Drupal Open Social that allows forceful browsing (accessing restricted pages without prope...
Jan 9, 2025This vulnerability allows unauthenticated attackers to modify order statuses in WordPress sites using the Shopping Cart & eCommerce Store plugin. Atta...
Jan 8, 2025The SureForms WordPress plugin has an information exposure vulnerability that allows unauthenticated attackers to export data from password-protected,...
Jan 8, 2025This CVE describes a Missing Authorization vulnerability in the WP SecureSubmit WordPress plugin that allows unauthorized access to sensitive data. At...
Jan 7, 2025This CVE describes a Missing Authorization vulnerability in the Saoshyant Page Builder WordPress plugin that allows attackers to exploit incorrectly c...
Jan 7, 2025The Jupiter X Core WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export popup templates. This af...
Jan 7, 2025The Export Import Menus WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export WordPress menu data...
Jan 7, 2025This vulnerability allows unauthenticated attackers to delete database data in the Ultimate Popup Creator WordPress plugin. Any WordPress site using v...
Jan 7, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free