CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,061
Total CVEs
228
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,061)

CVE-2024-12559
5.3

The ClickDesigns WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify or delete the plugin's AP...

Jan 7, 2025
CVE-2024-55408
5.3

An improper access control vulnerability in the AsusSAIO.sys driver allows attackers to send crafted IOCTL requests to misuse driver functionality. Th...

Jan 6, 2025
CVE-2024-56238
5.3

This CVE describes a missing authorization vulnerability in the QuantumCloud Floating Action Buttons WordPress plugin that allows attackers to access ...

Jan 2, 2025
CVE-2023-47515
5.3

This CVE describes a Missing Authorization vulnerability in the Seers WordPress plugin that allows attackers to exploit incorrectly configured access ...

Jan 2, 2025
CVE-2023-46637
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Generate Dummy Posts plugin that allows attackers to exploit incorrectly con...

Jan 2, 2025
CVE-2023-46606
5.3

This CVE describes a missing authorization vulnerability in the AtomChat WordPress plugin that allows attackers to bypass access controls. It affects ...

Jan 2, 2025
CVE-2023-46608
5.3

This CVE describes a Missing Authorization vulnerability in the WPDO DoLogin Security WordPress plugin that allows attackers to bypass access controls...

Jan 2, 2025
CVE-2023-46309
5.3

This CVE describes a Missing Authorization vulnerability in the wpDiscuz WordPress plugin that allows attackers to exploit incorrectly configured acce...

Jan 2, 2025
CVE-2023-45766
5.3

This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured ac...

Jan 2, 2025
CVE-2023-46073
5.3

This CVE describes a Missing Authorization vulnerability in the DX Delete Attached Media WordPress plugin that allows attackers to exploit incorrectly...

Jan 2, 2025
CVE-2023-46083
5.3

This CVE describes a missing authorization vulnerability in Kali Forms WordPress plugin that allows attackers to bypass access controls and perform un...

Jan 2, 2025
CVE-2023-45061
5.3

This CVE describes a Missing Authorization vulnerability in the WP Job Openings WordPress plugin by AWSM Innovations, allowing attackers to exploit in...

Jan 2, 2025
CVE-2023-44258
5.3

This CVE describes a Missing Authorization vulnerability in Schema App Structured Data WordPress plugin that allows attackers to exploit incorrectly c...

Jan 2, 2025
CVE-2024-49694
5.3

This CVE describes a Missing Authorization vulnerability in the My Wp Brand WordPress plugin that allows unauthorized users to access administrative f...

Dec 31, 2024
CVE-2024-56349
5.3

This vulnerability in JetBrains TeamCity allows unauthorized users to modify build logs due to improper access control. It affects organizations using...

Dec 20, 2024
CVE-2024-56009
5.3

This CVE describes a Missing Authorization vulnerability in the Spreadr Woocommerce WordPress plugin that allows attackers to access functionality not...

Dec 16, 2024
CVE-2024-55993
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Job Board Manager plugin that allows attackers to bypass access controls. It...

Dec 16, 2024
CVE-2024-54417
5.3

This CVE describes a missing authorization vulnerability in the Pixelgrade PixProof WordPress plugin that allows attackers to access functionality not...

Dec 16, 2024
CVE-2023-44149
5.3

This CVE describes a missing authorization vulnerability in the BeRocket Brands for WooCommerce WordPress plugin that allows attackers to bypass acces...

Dec 13, 2024
CVE-2023-41848
5.3

This CVE describes a missing authorization vulnerability in the Carousel Slider WordPress plugin that allows attackers to exploit incorrectly configur...

Dec 13, 2024
CVE-2023-41690
5.3

This vulnerability allows attackers to bypass authorization controls in the WiserNotify Social Proof WordPress plugin, potentially accessing restricte...

Dec 13, 2024
CVE-2023-40005
5.3

This CVE describes a Missing Authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to exploit incorrectly c...

Dec 13, 2024
CVE-2023-39996
5.3

This vulnerability allows attackers to bypass authorization controls in the WP OnlineSupport Essential Plugin Accordion and Accordion Slider for WordP...

Dec 13, 2024
CVE-2023-38480
5.3

This CVE describes a missing authorization vulnerability in the Booster Elementor Addons WordPress plugin that allows attackers to exploit incorrectly...

Dec 13, 2024
CVE-2023-37969
5.3

This CVE describes a missing authorization vulnerability in the Checkout with Zelle on Woocommerce WordPress plugin that allows attackers to bypass ac...

Dec 13, 2024
CVE-2023-36528
5.3

This vulnerability allows attackers to manipulate star ratings on WordPress sites without proper authorization by exploiting IP spoofing. It affects a...

Dec 13, 2024
CVE-2023-35777
5.3

This CVE describes a missing authorization vulnerability in The Events Calendar WordPress plugin that allows attackers to bypass access controls and p...

Dec 13, 2024
CVE-2023-36506
5.3

This CVE describes a missing authorization vulnerability in the YITH WooCommerce Waiting List plugin for WordPress. It allows attackers to bypass acce...

Dec 13, 2024
CVE-2023-34381
5.3

This CVE describes a missing authorization vulnerability in the Zippy WordPress plugin that allows attackers to bypass access controls. Attackers can ...

Dec 13, 2024
CVE-2023-32963
5.3

This CVE describes a missing authorization vulnerability in the WooCommerce Predictive Search plugin that allows attackers to bypass access controls a...

Dec 13, 2024
CVE-2022-47429
5.3

This CVE describes a Missing Authorization vulnerability in the 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress plugin that all...

Dec 13, 2024
CVE-2023-22697
5.3

This CVE describes a missing authorization vulnerability in the Survey Maker WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 13, 2024
CVE-2022-46846
5.3

This CVE describes a missing authorization vulnerability in the WordPress plugin 'Trending/Popular Post Slider and Widget' that allows attackers to ex...

Dec 13, 2024
CVE-2024-52391
5.3

This CVE describes a Missing Authorization vulnerability in the Pie Register Premium WordPress plugin that allows unauthorized users to access functio...

Dec 9, 2024
CVE-2023-41953
5.3

This CVE describes a missing authorization vulnerability in the ProfilePress WordPress plugin that allows unauthorized users to access restricted func...

Dec 9, 2024
CVE-2023-51362
5.3

This CVE describes a missing authorization vulnerability in the WordPress plugin 'All-in-one Floating Contact Form – My Sticky Elements', allowing a...

Dec 9, 2024
CVE-2023-50904
5.3

This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured ac...

Dec 9, 2024
CVE-2023-50375
5.3

This CVE describes a Missing Authorization vulnerability in the Translate AI Multilingual Solutions Google Language Translator WordPress plugin, allow...

Dec 9, 2024
CVE-2023-49850
5.3

This vulnerability allows attackers to bypass authorization controls in the WP Simple HTML Sitemap WordPress plugin, potentially accessing restricted ...

Dec 9, 2024
CVE-2023-49192
5.3

This CVE describes a missing authorization vulnerability in the Clever Widgets Enhanced Text Widget WordPress plugin. It allows attackers to exploit i...

Dec 9, 2024
CVE-2023-47847
5.3

This CVE describes a Missing Authorization vulnerability in PayTR Taksit Tablosu WordPress plugin that allows attackers to exploit incorrectly configu...

Dec 9, 2024
CVE-2023-47832
5.3

This CVE describes a Missing Authorization vulnerability in the SearchIQ WordPress plugin that allows attackers to exploit incorrectly configured acce...

Dec 9, 2024
CVE-2023-47805
5.3

This CVE describes a missing authorization vulnerability in the WPCafe WordPress plugin that allows attackers to bypass access controls. Attackers can...

Dec 9, 2024
CVE-2023-32293
5.3

This vulnerability allows attackers to bypass authorization controls in the WRC Pricing Tables WordPress plugin, potentially accessing or modifying pr...

Dec 9, 2024
CVE-2023-29429
5.3

This CVE describes a missing authorization vulnerability in the WPEverest User Registration WordPress plugin that allows attackers to bypass access co...

Dec 9, 2024
CVE-2023-30479
5.3

This CVE describes a Missing Authorization vulnerability in the Stamped.io Product Reviews & UGC for WooCommerce WordPress plugin. It allows attackers...

Dec 9, 2024
CVE-2023-30488
5.3

This CVE describes a missing authorization vulnerability in the WordPress Featured Post Creative plugin that allows attackers to bypass access control...

Dec 9, 2024
CVE-2023-29173
5.3

This CVE describes a missing authorization vulnerability in the AWESOME TOGI Product Category Tree WordPress plugin that allows attackers to exploit i...

Dec 9, 2024
CVE-2023-25455
5.3

This CVE describes a Missing Authorization vulnerability in the miniOrange WordPress Social Login and Register plugin that allows attackers to delete ...

Dec 9, 2024
CVE-2023-23975
5.3

This vulnerability allows attackers to bypass authorization controls in the Quick Event Manager WordPress plugin, potentially accessing or modifying d...

Dec 9, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free