CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,061
Total CVEs
228
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,061)

CVE-2023-25048
5.3

This CVE describes a missing authorization vulnerability in the Fantastic Content Protector Free WordPress plugin. It allows attackers to bypass acces...

Dec 9, 2024
CVE-2023-23893
5.3

CVE-2023-23893 is a missing authorization vulnerability in the Simple Giveaways WordPress plugin that allows attackers to bypass access controls and p...

Dec 9, 2024
CVE-2024-53826
5.3

This CVE describes a Missing Authorization vulnerability in the WPSight WPCasa WordPress plugin that allows attackers to access functionality not prop...

Dec 6, 2024
CVE-2024-53795
5.3

This CVE describes a broken access control vulnerability in the Church Admin WordPress plugin where missing authorization allows users to access funct...

Dec 6, 2024
CVE-2024-9706
5.3

The Ultimate Coming Soon & Maintenance WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to change the...

Dec 6, 2024
CVE-2024-10813
5.3

The Product Table for WooCommerce plugin for WordPress exposes sensitive information through the var_dump_table parameter, allowing unauthenticated at...

Nov 23, 2024
CVE-2024-10802
5.3

The Hash Elements WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to retrieve draft post titles. This...

Nov 13, 2024
CVE-2024-10531
5.3

The Kognetiks Chatbot for WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or h...

Nov 13, 2024
CVE-2024-10529
5.3

The Kognetiks Chatbot for WordPress plugin has a missing capability check in the delete_assistant() function, allowing authenticated users with subscr...

Nov 13, 2024
CVE-2024-9578
5.3

The Hide Links WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes through comment text. This affects all WordPress site...

Nov 13, 2024
CVE-2024-47358
5.3

This CVE describes a missing authorization vulnerability in the Popup Maker WordPress plugin that allows attackers to access functionality not properl...

Nov 1, 2024
CVE-2024-43919
5.3

CVE-2024-43919 is a broken access control vulnerability in the YARPP WordPress plugin that allows unauthorized users to perform actions they shouldn't...

Nov 1, 2024
CVE-2024-43290
5.3

This CVE describes a Missing Authorization vulnerability in the Atarim WordPress plugin that allows attackers to access functionality not properly con...

Nov 1, 2024
CVE-2024-43277
5.3

This CVE describes a Missing Authorization vulnerability in the UsersWP WordPress plugin that allows attackers to exploit incorrectly configured acces...

Nov 1, 2024
CVE-2024-43219
5.3

This CVE describes a Missing Authorization vulnerability in the Persian WooCommerce WordPress plugin that allows attackers to access functionality not...

Nov 1, 2024
CVE-2024-39625
5.3

CVE-2024-39625 is a missing authorization vulnerability in the Icegram Engage WordPress plugin that allows unauthenticated attackers to duplicate mess...

Nov 1, 2024
CVE-2024-38792
5.3

This CVE describes a Missing Authorization vulnerability in the ConveyThis Translate plugin for WordPress. It allows attackers to access functionality...

Nov 1, 2024
CVE-2024-38748
5.3

This CVE describes a broken access control vulnerability in TheInnovs EleForms WordPress plugin that allows unauthorized users to perform actions they...

Nov 1, 2024
CVE-2024-38743
5.3

This CVE describes a broken access control vulnerability in the Upqode Plum: Spin Wheel & Email Pop-up WordPress plugin. It allows unauthorized users ...

Nov 1, 2024
CVE-2024-38702
5.3

This CVE describes a missing authorization vulnerability in the Product Delivery Date for WooCommerce Lite plugin that allows attackers to access func...

Nov 1, 2024
CVE-2024-37926
5.3

This vulnerability allows unauthorized users to access functionality that should be restricted to authorized users only in the WP Accessibility Helper...

Nov 1, 2024
CVE-2024-38690
5.3

This CVE describes a Missing Authorization vulnerability in the iPanorama 360 WordPress plugin that allows attackers to access functionality not prope...

Nov 1, 2024
CVE-2024-37468
5.3

CVE-2024-37468 is a missing authorization vulnerability in the Newsmatic WordPress theme that allows attackers to bypass access controls and perform u...

Nov 1, 2024
CVE-2024-37444
5.3

This CVE describes a missing authorization vulnerability in the WPMU DEV Defender Security WordPress plugin that allows attackers to access functional...

Nov 1, 2024
CVE-2024-37456
5.3

This CVE describes a missing authorization vulnerability in the Noptin Newsletter WordPress plugin that allows attackers to access functionality not p...

Nov 1, 2024
CVE-2024-37427
5.3

CVE-2024-37427 is a missing authorization vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to bypass access controls and...

Nov 1, 2024
CVE-2024-37276
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Featured Image from URL (FIFU) plugin that allows attackers to exploit incor...

Nov 1, 2024
CVE-2024-37255
5.3

This CVE describes a missing authorization vulnerability in the Wpmet Elements Kit Elementor addons plugin for WordPress. It allows unauthenticated at...

Nov 1, 2024
CVE-2024-37226
5.3

This CVE describes a Missing Authorization vulnerability in the Kanban for WordPress plugin that allows attackers to exploit incorrectly configured ac...

Nov 1, 2024
CVE-2024-37119
5.3

This vulnerability allows unauthenticated attackers to reset license settings in Uncanny Automator Pro WordPress plugin. It affects all WordPress site...

Nov 1, 2024
CVE-2024-50422
5.3

This CVE describes a missing authorization vulnerability in the Cloudways Breeze WordPress plugin that allows attackers to bypass access controls. It ...

Oct 29, 2024
CVE-2024-49683
5.3

This CVE describes a Missing Authorization vulnerability in the Schema & Structured Data for WP & AMP WordPress plugin. It allows attackers to access ...

Oct 24, 2024
CVE-2024-43924
5.3

This CVE describes a missing authorization vulnerability in the dFactory Responsive Lightbox WordPress plugin that allows attackers to access function...

Oct 23, 2024
CVE-2024-9671
5.3

This CVE describes an authentication bypass vulnerability in 3Scale where unauthorized users can access PDF invoices of Developer users by knowing or ...

Oct 9, 2024
CVE-2024-9189
5.3

This vulnerability allows unauthenticated attackers to modify VAT status for any WooCommerce order via the EU/UK VAT Manager plugin. All WordPress sit...

Sep 28, 2024
CVE-2024-6845
5.3

The Chatbot with ChatGPT WordPress plugin before version 2.4.6 has an authorization flaw in a REST endpoint that allows unauthenticated attackers to r...

Sep 25, 2024
CVE-2024-40852
5.3

This vulnerability allows an attacker with physical access to a locked iOS/iPadOS device to view recent photos without authentication through the Assi...

Sep 17, 2024
CVE-2024-8369
5.3

The EventPrime WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view private or password-protected ...

Sep 10, 2024
CVE-2024-7447
5.3

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Funnelforms Free plugin. Any WordPress site...

Aug 28, 2024
CVE-2024-43214
5.3

This CVE describes a Missing Authorization vulnerability in the myCred WordPress plugin that allows unauthorized users to access sensitive data. It af...

Aug 26, 2024
CVE-2024-35686
5.3

This CVE describes a missing authorization vulnerability in WordPress Sensei LMS plugins that allows unauthorized users to access restricted functiona...

Aug 18, 2024
CVE-2023-4730
5.3

The LadiApp WordPress plugin versions up to 4.3 contain an authentication bypass vulnerability that allows unauthenticated attackers to modify plugin ...

Aug 17, 2024
CVE-2023-4025
5.3

The Radio Player WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify player instances. This aff...

Aug 17, 2024
CVE-2024-6489
5.3

The Getwid WordPress plugin has a missing capability check vulnerability that allows authenticated users with Contributor-level access or higher to mo...

Jul 20, 2024
CVE-2024-0619
5.3

The Payflex Payment Gateway WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to modify order status...

Jul 11, 2024
CVE-2024-23504
5.3

This CVE describes a Missing Authorization vulnerability in the Ninja Tables WordPress plugin by WPManageNinja LLC. It allows unauthorized users to pe...

Jun 14, 2024
CVE-2023-37394
5.3

This CVE describes a Missing Authorization vulnerability in the WP Dummy Content Generator WordPress plugin. It allows attackers to perform unauthoriz...

Jun 14, 2024
CVE-2023-41240
5.3

This vulnerability allows unauthorized users to access functionality intended only for administrators in the Vark Pricing Deals for WooCommerce WordPr...

Jun 12, 2024
CVE-2023-40603
5.3

CVE-2023-40603 is a missing authorization vulnerability in the Simple Org Chart WordPress plugin that allows unauthorized users to perform actions tha...

Jun 12, 2024
CVE-2024-34763
5.3

This CVE describes a missing authorization vulnerability in the Builder for WooCommerce reviews shortcodes – ReviewShort WordPress plugin. It allows...

Jun 11, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free