CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,061)
The ClickDesigns WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify or delete the plugin's AP...
Jan 7, 2025An improper access control vulnerability in the AsusSAIO.sys driver allows attackers to send crafted IOCTL requests to misuse driver functionality. Th...
Jan 6, 2025This CVE describes a missing authorization vulnerability in the QuantumCloud Floating Action Buttons WordPress plugin that allows attackers to access ...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the Seers WordPress plugin that allows attackers to exploit incorrectly configured access ...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Generate Dummy Posts plugin that allows attackers to exploit incorrectly con...
Jan 2, 2025This CVE describes a missing authorization vulnerability in the AtomChat WordPress plugin that allows attackers to bypass access controls. It affects ...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the WPDO DoLogin Security WordPress plugin that allows attackers to bypass access controls...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the wpDiscuz WordPress plugin that allows attackers to exploit incorrectly configured acce...
Jan 2, 2025This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured ac...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the DX Delete Attached Media WordPress plugin that allows attackers to exploit incorrectly...
Jan 2, 2025This CVE describes a missing authorization vulnerability in Kali Forms WordPress plugin that allows attackers to bypass access controls and perform un...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the WP Job Openings WordPress plugin by AWSM Innovations, allowing attackers to exploit in...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in Schema App Structured Data WordPress plugin that allows attackers to exploit incorrectly c...
Jan 2, 2025This CVE describes a Missing Authorization vulnerability in the My Wp Brand WordPress plugin that allows unauthorized users to access administrative f...
Dec 31, 2024This vulnerability in JetBrains TeamCity allows unauthorized users to modify build logs due to improper access control. It affects organizations using...
Dec 20, 2024This CVE describes a Missing Authorization vulnerability in the Spreadr Woocommerce WordPress plugin that allows attackers to access functionality not...
Dec 16, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Job Board Manager plugin that allows attackers to bypass access controls. It...
Dec 16, 2024This CVE describes a missing authorization vulnerability in the Pixelgrade PixProof WordPress plugin that allows attackers to access functionality not...
Dec 16, 2024This CVE describes a missing authorization vulnerability in the BeRocket Brands for WooCommerce WordPress plugin that allows attackers to bypass acces...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Carousel Slider WordPress plugin that allows attackers to exploit incorrectly configur...
Dec 13, 2024This vulnerability allows attackers to bypass authorization controls in the WiserNotify Social Proof WordPress plugin, potentially accessing restricte...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to exploit incorrectly c...
Dec 13, 2024This vulnerability allows attackers to bypass authorization controls in the WP OnlineSupport Essential Plugin Accordion and Accordion Slider for WordP...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Booster Elementor Addons WordPress plugin that allows attackers to exploit incorrectly...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Checkout with Zelle on Woocommerce WordPress plugin that allows attackers to bypass ac...
Dec 13, 2024This vulnerability allows attackers to manipulate star ratings on WordPress sites without proper authorization by exploiting IP spoofing. It affects a...
Dec 13, 2024This CVE describes a missing authorization vulnerability in The Events Calendar WordPress plugin that allows attackers to bypass access controls and p...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the YITH WooCommerce Waiting List plugin for WordPress. It allows attackers to bypass acce...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Zippy WordPress plugin that allows attackers to bypass access controls. Attackers can ...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the WooCommerce Predictive Search plugin that allows attackers to bypass access controls a...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress plugin that all...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Survey Maker WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the WordPress plugin 'Trending/Popular Post Slider and Widget' that allows attackers to ex...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the Pie Register Premium WordPress plugin that allows unauthorized users to access functio...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the ProfilePress WordPress plugin that allows unauthorized users to access restricted func...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WordPress plugin 'All-in-one Floating Contact Form – My Sticky Elements', allowing a...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured ac...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Translate AI Multilingual Solutions Google Language Translator WordPress plugin, allow...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the WP Simple HTML Sitemap WordPress plugin, potentially accessing restricted ...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Clever Widgets Enhanced Text Widget WordPress plugin. It allows attackers to exploit i...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in PayTR Taksit Tablosu WordPress plugin that allows attackers to exploit incorrectly configu...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the SearchIQ WordPress plugin that allows attackers to exploit incorrectly configured acce...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WPCafe WordPress plugin that allows attackers to bypass access controls. Attackers can...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the WRC Pricing Tables WordPress plugin, potentially accessing or modifying pr...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WPEverest User Registration WordPress plugin that allows attackers to bypass access co...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Stamped.io Product Reviews & UGC for WooCommerce WordPress plugin. It allows attackers...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WordPress Featured Post Creative plugin that allows attackers to bypass access control...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the AWESOME TOGI Product Category Tree WordPress plugin that allows attackers to exploit i...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the miniOrange WordPress Social Login and Register plugin that allows attackers to delete ...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the Quick Event Manager WordPress plugin, potentially accessing or modifying d...
Dec 9, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free