CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,061
Total CVEs
228
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,061)

CVE-2025-31863
5.3

This CVE describes a missing authorization vulnerability in the Agency Toolkit WordPress plugin that allows attackers to bypass intended access contro...

Apr 1, 2025
CVE-2025-31848
5.3

This CVE describes a missing authorization vulnerability in the WordPress Adverts Plugin that allows attackers to bypass access controls and perform u...

Apr 1, 2025
CVE-2025-31810
5.3

This CVE describes a missing authorization vulnerability in the WordPress Question Answer plugin that allows attackers to access functionality not pro...

Apr 1, 2025
CVE-2025-31786
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Simple Icons plugin that allows attackers to bypass access controls. It affe...

Apr 1, 2025
CVE-2025-31774
5.3

This CVE describes a Missing Authorization vulnerability in WebProtect.ai Astra Security Suite WordPress plugin that allows attackers to bypass access...

Apr 1, 2025
CVE-2025-31765
5.3

This CVE describes a Missing Authorization vulnerability in the GDPR Cookie Notice WordPress plugin that allows attackers to exploit incorrectly confi...

Apr 1, 2025
CVE-2025-31618
5.3

This vulnerability allows attackers to bypass authorization controls in the Jaap Jansma Connector to CiviCRM with CiviMcRestFace WordPress plugin. Att...

Mar 31, 2025
CVE-2025-31386
5.3

This CVE describes a Missing Authorization vulnerability in Simple:Press WordPress plugin that allows attackers to bypass access controls and perform ...

Mar 31, 2025
CVE-2025-22739
5.3

This CVE describes a missing authorization vulnerability in the LearnPress WordPress plugin that allows attackers to bypass access controls. It affect...

Mar 27, 2025
CVE-2025-22629
5.3

This CVE describes a missing authorization vulnerability in the iNET Webkit WordPress plugin that allows attackers to access functionality not properl...

Mar 27, 2025
CVE-2025-30887
5.3

This CVE describes a Missing Authorization vulnerability in the WpEvently WordPress plugin that allows attackers to bypass access controls. Attackers ...

Mar 27, 2025
CVE-2025-30839
5.3

This CVE describes a missing authorization vulnerability in the Taxi Booking Manager for WooCommerce WordPress plugin. Attackers can exploit incorrect...

Mar 27, 2025
CVE-2025-30830
5.3

This CVE describes a Missing Authorization vulnerability in the Hossni Mubarak Cool Author Box WordPress plugin that allows attackers to exploit incor...

Mar 27, 2025
CVE-2025-30821
5.3

This CVE describes a missing authorization vulnerability in the SNORDIAN's H5PxAPIkatchu WordPress plugin that allows attackers to access functionalit...

Mar 27, 2025
CVE-2025-30591
5.3

This CVE describes a Missing Authorization vulnerability in the Music Press Pro WordPress plugin that allows attackers to bypass access controls. It a...

Mar 24, 2025
CVE-2025-30581
5.3

This CVE describes a missing authorization vulnerability in the PluginOps Top Bar WordPress plugin that allows attackers to bypass access controls. It...

Mar 24, 2025
CVE-2025-2290
5.3

The LifterLMS WordPress plugin has an unauthenticated post trashing vulnerability that allows attackers without credentials to move all published post...

Mar 19, 2025
CVE-2025-1507
5.3

This vulnerability in the ShareThis Dashboard for Google Analytics WordPress plugin allows unauthenticated attackers to disable all plugin features by...

Mar 14, 2025
CVE-2025-1285
5.3

This vulnerability in the Resido WordPress theme allows unauthenticated attackers to delete or save API keys without proper authorization checks. Any ...

Mar 14, 2025
CVE-2025-1508
5.3

The WP Crowdfunding WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to down...

Mar 12, 2025
CVE-2025-28872
5.3

This CVE describes a missing authorization vulnerability in the WordPress plugin Block Spam By Math Reloaded that allows attackers to access functiona...

Mar 11, 2025
CVE-2024-12610
5.3

This vulnerability in the School Management System for WordPress plugin allows unauthenticated attackers to delete arbitrary posts due to missing capa...

Mar 7, 2025
CVE-2024-8682
5.3

This vulnerability allows unauthenticated attackers to register user accounts on WordPress sites using the JNews theme, even when user registration is...

Mar 5, 2025
CVE-2025-1502
5.3

The IP2Location Redirection plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to download the plug...

Mar 1, 2025
CVE-2025-1249
5.3

This CVE describes a missing authorization vulnerability in the Pixelite Events Manager WordPress plugin that allows attackers to exploit incorrectly ...

Feb 26, 2025
CVE-2025-1402
5.3

This vulnerability in the Event Tickets and Registration WordPress plugin allows authenticated attackers with Contributor-level access or higher to de...

Feb 21, 2025
CVE-2025-1483
5.3

The LTL Freight Quotes – GlobalTranz Edition WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to mo...

Feb 20, 2025
CVE-2024-13520
5.3

This vulnerability allows unauthenticated attackers to modify gift voucher values, expiration dates, and user notes in WordPress sites using the Gift ...

Feb 20, 2025
CVE-2024-13364
5.3

The Raptive Ads WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to reset ad and cls files. This affec...

Feb 19, 2025
CVE-2024-13231
5.3

The WordPress Portfolio Builder plugin has an authorization bypass vulnerability that allows unauthenticated attackers to add arbitrary videos to any ...

Feb 19, 2025
CVE-2024-13719
5.3

The PeproDev Ultimate Invoice WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to view inv...

Feb 19, 2025
CVE-2024-13554
5.3

The WP Extended WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to reorder posts. This affects all Wo...

Feb 12, 2025
CVE-2025-23187
5.3

This vulnerability allows unauthenticated attackers to generate technical metadata in SAP systems via an RFC-enabled function module in transaction SD...

Feb 11, 2025
CVE-2024-12184
5.3

This vulnerability in the WordPress Contact Forms by Cimatti plugin allows unauthenticated attackers to download form submissions containing potential...

Feb 1, 2025
CVE-2025-24662
5.3

This CVE describes a missing authorization vulnerability in LearnDash LMS WordPress plugin that allows attackers to bypass access controls and access ...

Jan 27, 2025
CVE-2025-24600
5.3

CVE-2025-24600 is a missing authorization vulnerability in the RSVPMaker WordPress plugin that allows unauthorized users to access restricted function...

Jan 27, 2025
CVE-2025-24705
5.3

This vulnerability allows unauthorized users to access sensitive data in WooCommerce Quick View plugin due to missing authorization checks. It affects...

Jan 24, 2025
CVE-2025-21514
5.3

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers with network access via HTTP to read sensitive data. It a...

Jan 21, 2025
CVE-2024-12104
5.3

The Atarim WordPress plugin has a vulnerability that allows unauthenticated attackers to delete project pages and files without proper authorization. ...

Jan 21, 2025
CVE-2024-12071
5.3

This vulnerability in the Evergreen Content Poster WordPress plugin allows unauthenticated attackers to delete arbitrary posts and pages due to missin...

Jan 18, 2025
CVE-2025-23862
5.3

This vulnerability allows attackers to bypass authorization controls in the Contact Form 7 Anti Spambot WordPress plugin, potentially accessing admini...

Jan 16, 2025
CVE-2025-23514
5.3

This CVE describes a Missing Authorization vulnerability in the Sanjaysolutions Loginplus WordPress plugin that allows attackers to access functionali...

Jan 16, 2025
CVE-2024-13312
5.3

This CVE describes a Missing Authorization vulnerability in Drupal Open Social that allows forceful browsing (accessing restricted pages without prope...

Jan 9, 2025
CVE-2024-12712
5.3

This vulnerability allows unauthenticated attackers to modify order statuses in WordPress sites using the Shopping Cart & eCommerce Store plugin. Atta...

Jan 8, 2025
CVE-2024-12713
5.3

The SureForms WordPress plugin has an information exposure vulnerability that allows unauthenticated attackers to export data from password-protected,...

Jan 8, 2025
CVE-2024-56270
5.3

This CVE describes a Missing Authorization vulnerability in the WP SecureSubmit WordPress plugin that allows unauthorized access to sensitive data. At...

Jan 7, 2025
CVE-2025-22560
5.3

This CVE describes a Missing Authorization vulnerability in the Saoshyant Page Builder WordPress plugin that allows attackers to exploit incorrectly c...

Jan 7, 2025
CVE-2024-12316
5.3

The Jupiter X Core WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export popup templates. This af...

Jan 7, 2025
CVE-2024-10866
5.3

The Export Import Menus WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to export WordPress menu data...

Jan 7, 2025
CVE-2024-12158
5.3

This vulnerability allows unauthenticated attackers to delete database data in the Ultimate Popup Creator WordPress plugin. Any WordPress site using v...

Jan 7, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free