CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,061)
This CVE describes a Missing Authorization vulnerability in the Contact List PRO WordPress plugin that allows unauthorized users to perform actions in...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the SoftLab Radio Player WordPress plugin, allowing unauthorized users to perform actions ...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Happyforms WordPress plugin that allows unauthorized users to perform actions that sho...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Insert Post Ads plugin. It allows attackers to perform unauthorized actions ...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the WooCommerce Canada Post Shipping plugin for WordPress. It allows unauthorized users to...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Leyka WordPress plugin that allows unauthorized users to perform actions requiring aut...
Jun 11, 2024CVE-2024-34442 is a missing authorization vulnerability in the weDocs WordPress plugin that allows unauthorized users to access or modify documentatio...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Tickera WordPress plugin that allows unauthorized users to perform actions they should...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the PilotPress WordPress plugin by ONTRAPORT Inc. It allows unauthorized users to access f...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the AdFoxly WordPress plugin that allows unauthorized users to perform privileged actions....
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Olive One Click Demo Import plugin that allows arbitrary file download. Atta...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Social Share Pro WordPress plugin (also known as Social Share Icons & Social Share But...
Jun 9, 2024This vulnerability allows attackers to bypass authorization checks in the Advanced Local Pickup for WooCommerce WordPress plugin. Unauthorized users c...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Avirtum Vision Interactive WordPress plugin (Vision Image Map Builder). It allows unau...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress EmbedPress plugin that allows unauthorized users to perform actions intended...
Jun 9, 2024This CVE describes a missing authorization vulnerability in the Tainacan WordPress plugin that allows unauthorized users to perform actions they shoul...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in WooCommerce Product Vendors plugin for WordPress. It allows unauthorized users to perform ...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress 'Import and export users and customers' plugin. It allows unauthorized users...
Jun 8, 2024The WP-Recall plugin for WordPress has a missing capability check that allows unauthenticated attackers to delete arbitrary payment records. This affe...
Jun 6, 2024The Testimonial Carousel For Elementor WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify plug...
May 25, 2024This CVE describes a Missing Authorization vulnerability in the Flothemes Flo Forms WordPress plugin. It allows unauthorized users to perform actions ...
May 17, 2024CVE-2023-34186 is a Missing Authorization vulnerability in the Imran Sayed Headless CMS WordPress plugin that allows unauthorized users to access rest...
May 17, 2024This vulnerability allows unauthenticated attackers to bypass user registration controls in LearnPress WordPress LMS Plugin, enabling them to create a...
May 14, 2024The ShopLentor (formerly WooLentor) WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view all produ...
May 14, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Print My Blog plugin that allows unauthorized users to access functionality ...
May 6, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Post Grid Master plugin (also called AddonMaster Post Grid Master). It allow...
May 6, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WordPress Slider Carousel – Responsive Image Slider plugin. ...
May 3, 2024The Poll Maker WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to extract email addresses through character-...
May 2, 2024This vulnerability in the Analytify WordPress plugin allows unauthenticated attackers to modify the Google Analytics tracking ID without proper author...
May 2, 2024This vulnerability allows authenticated administrative users in SAP Business Workflow to bypass role-based access controls and perform unauthorized hi...
Feb 10, 2026This CVE describes a sandbox escape vulnerability in macOS where an application can bypass its security restrictions. It affects macOS systems running...
Dec 12, 2025CVE-2023-23715 is a missing authorization vulnerability in JobBoardWP WordPress plugin that allows attackers to delete job listings without proper aut...
Dec 9, 2024This CVE describes a macOS vulnerability where applications could bypass entitlement checks to access protected user data. It affects macOS Sonoma bef...
Sep 15, 2025A permission control vulnerability in Huawei's contacts module allows unauthorized access or manipulation of contact data. This affects Huawei devices...
May 6, 2025Kargo versions 1.9.0 to 1.9.2 have an authorization bypass vulnerability where three REST API endpoints omit the 'promote' verb check. This allows use...
Feb 20, 2026This vulnerability in SAP ABAP systems allows authenticated users to access system information without proper authorization checks. It affects SAP sys...
Feb 10, 2026This CVE describes a missing authorization vulnerability in the WCFM Marketplace WordPress plugin that allows attackers to bypass access controls. It ...
Dec 16, 2025This vulnerability allows authenticated GitLab users without project membership to view sensitive manual CI/CD variables via GraphQL API queries. It a...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the MaxiBlocks WordPress plugin that allows attackers to bypass access controls. Attackers...
Sep 22, 2025CVE-2025-42911 is an information disclosure vulnerability in SAP NetWeaver's Service Data Download component. Authenticated users can call a remote-en...
Sep 9, 2025This CVE describes a missing authorization vulnerability in the SaasLauncher WordPress theme that allows attackers to bypass access controls. Attacker...
Sep 3, 2025The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where it fails to verify user permissions when creatin...
Aug 11, 2025This vulnerability in SAP NetWeaver allows authenticated non-administrative users to call a remote-enabled function module that reveals non-sensitive ...
Jul 8, 2025This vulnerability in iTop allows authenticated users with portal access to modify object fields they shouldn't have permission to change. It affects ...
May 14, 2025This CVE describes a Missing Authorization vulnerability in the MapSVG Lite WordPress plugin that allows attackers to bypass access controls and perfo...
Apr 9, 2025This CVE describes a missing authorization vulnerability in the WpDevArt Booking Calendar plugin for WordPress. It allows attackers to bypass access c...
Dec 9, 2024The ImageRecycle WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify ...
Aug 24, 2024This vulnerability allows authenticated remote attackers to bypass SAML authorization controls in Cisco ASA/FTD VPN services. Attackers can intercept ...
May 22, 2024The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to list file...
May 22, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free