CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,061
Total CVEs
228
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
437
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,061)

CVE-2024-34821
5.3

This CVE describes a Missing Authorization vulnerability in the Contact List PRO WordPress plugin that allows unauthorized users to perform actions in...

Jun 11, 2024
CVE-2024-34753
5.3

This CVE describes a Missing Authorization vulnerability in the SoftLab Radio Player WordPress plugin, allowing unauthorized users to perform actions ...

Jun 11, 2024
CVE-2024-23521
5.3

This CVE describes a Missing Authorization vulnerability in the Happyforms WordPress plugin that allows unauthorized users to perform actions that sho...

Jun 11, 2024
CVE-2024-35665
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Insert Post Ads plugin. It allows attackers to perform unauthorized actions ...

Jun 11, 2024
CVE-2023-51498
5.3

This CVE describes a Missing Authorization vulnerability in the WooCommerce Canada Post Shipping plugin for WordPress. It allows unauthorized users to...

Jun 11, 2024
CVE-2024-35683
5.3

This CVE describes a Missing Authorization vulnerability in the Leyka WordPress plugin that allows unauthorized users to perform actions requiring aut...

Jun 11, 2024
CVE-2024-34442
5.3

CVE-2024-34442 is a missing authorization vulnerability in the weDocs WordPress plugin that allows unauthorized users to access or modify documentatio...

Jun 11, 2024
CVE-2024-35729
5.3

This CVE describes a Missing Authorization vulnerability in the Tickera WordPress plugin that allows unauthorized users to perform actions they should...

Jun 10, 2024
CVE-2024-23524
5.3

This CVE describes a Missing Authorization vulnerability in the PilotPress WordPress plugin by ONTRAPORT Inc. It allows unauthorized users to access f...

Jun 10, 2024
CVE-2024-34802
5.3

This CVE describes a Missing Authorization vulnerability in the AdFoxly WordPress plugin that allows unauthorized users to perform privileged actions....

Jun 9, 2024
CVE-2024-32715
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Olive One Click Demo Import plugin that allows arbitrary file download. Atta...

Jun 9, 2024
CVE-2024-32820
5.3

This CVE describes a Missing Authorization vulnerability in the Social Share Pro WordPress plugin (also known as Social Share Icons & Social Share But...

Jun 9, 2024
CVE-2024-32814
5.3

This vulnerability allows attackers to bypass authorization checks in the Advanced Local Pickup for WooCommerce WordPress plugin. Unauthorized users c...

Jun 9, 2024
CVE-2024-32779
5.3

This CVE describes a Missing Authorization vulnerability in the Avirtum Vision Interactive WordPress plugin (Vision Image Map Builder). It allows unau...

Jun 9, 2024
CVE-2024-31274
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress EmbedPress plugin that allows unauthorized users to perform actions intended...

Jun 9, 2024
CVE-2024-30529
5.3

This CVE describes a missing authorization vulnerability in the Tainacan WordPress plugin that allows unauthorized users to perform actions they shoul...

Jun 9, 2024
CVE-2024-30539
5.3

This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...

Jun 9, 2024
CVE-2023-51494
5.3

This CVE describes a Missing Authorization vulnerability in WooCommerce Product Vendors plugin for WordPress. It allows unauthorized users to perform ...

Jun 9, 2024
CVE-2024-22151
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress 'Import and export users and customers' plugin. It allows unauthorized users...

Jun 8, 2024
CVE-2024-1175
5.3

The WP-Recall plugin for WordPress has a missing capability check that allows unauthenticated attackers to delete arbitrary payment records. This affe...

Jun 6, 2024
CVE-2024-4858
5.3

The Testimonial Carousel For Elementor WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify plug...

May 25, 2024
CVE-2024-35174
5.3

This CVE describes a Missing Authorization vulnerability in the Flothemes Flo Forms WordPress plugin. It allows unauthorized users to perform actions ...

May 17, 2024
CVE-2023-34186
5.3

CVE-2023-34186 is a Missing Authorization vulnerability in the Imran Sayed Headless CMS WordPress plugin that allows unauthorized users to access rest...

May 17, 2024
CVE-2024-4444
5.3

This vulnerability allows unauthenticated attackers to bypass user registration controls in LearnPress WordPress LMS Plugin, enabling them to create a...

May 14, 2024
CVE-2023-6327
5.3

The ShopLentor (formerly WooLentor) WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view all produ...

May 14, 2024
CVE-2024-33907
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Print My Blog plugin that allows unauthorized users to access functionality ...

May 6, 2024
CVE-2024-34372
5.3

This CVE describes a Missing Authorization vulnerability in the WordPress Post Grid Master plugin (also called AddonMaster Post Grid Master). It allow...

May 6, 2024
CVE-2023-25457
5.3

This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WordPress Slider Carousel – Responsive Image Slider plugin. ...

May 3, 2024
CVE-2024-3601
5.3

The Poll Maker WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to extract email addresses through character-...

May 2, 2024
CVE-2024-1584
5.3

This vulnerability in the Analytify WordPress plugin allows unauthenticated attackers to modify the Google Analytics tracking ID without proper author...

May 2, 2024
CVE-2026-24312
5.2

This vulnerability allows authenticated administrative users in SAP Business Workflow to bypass role-based access controls and perform unauthorized hi...

Feb 10, 2026
CVE-2025-43497
5.2

This CVE describes a sandbox escape vulnerability in macOS where an application can bypass its security restrictions. It affects macOS systems running...

Dec 12, 2025
CVE-2023-23715
5.2

CVE-2023-23715 is a missing authorization vulnerability in JobBoardWP WordPress plugin that allows attackers to delete job listings without proper aut...

Dec 9, 2024
CVE-2025-43311
5.1

This CVE describes a macOS vulnerability where applications could bypass entitlement checks to access protected user data. It affects macOS Sonoma bef...

Sep 15, 2025
CVE-2025-46586
5.1

A permission control vulnerability in Huawei's contacts module allows unauthorized access or manipulation of contact data. This affects Huawei devices...

May 6, 2025
CVE-2026-27111
5.0

Kargo versions 1.9.0 to 1.9.2 have an authorization bypass vulnerability where three REST API endpoints omit the 'promote' verb check. This allows use...

Feb 20, 2026
CVE-2026-0486
5.0

This vulnerability in SAP ABAP systems allows authenticated users to access system information without proper authorization checks. It affects SAP sys...

Feb 10, 2026
CVE-2025-64631
5.0

This CVE describes a missing authorization vulnerability in the WCFM Marketplace WordPress plugin that allows attackers to bypass access controls. It ...

Dec 16, 2025
CVE-2025-9825
5.0

This vulnerability allows authenticated GitLab users without project membership to view sensitive manual CI/CD variables via GraphQL API queries. It a...

Nov 21, 2025
CVE-2025-58968
5.0

This CVE describes a Missing Authorization vulnerability in the MaxiBlocks WordPress plugin that allows attackers to bypass access controls. Attackers...

Sep 22, 2025
CVE-2025-42911
5.0

CVE-2025-42911 is an information disclosure vulnerability in SAP NetWeaver's Service Data Download component. Authenticated users can call a remote-en...

Sep 9, 2025
CVE-2025-58606
5.0

This CVE describes a missing authorization vulnerability in the SaasLauncher WordPress theme that allows attackers to bypass access controls. Attacker...

Sep 3, 2025
CVE-2025-54458
5.0

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where it fails to verify user permissions when creatin...

Aug 11, 2025
CVE-2025-42968
5.0

This vulnerability in SAP NetWeaver allows authenticated non-administrative users to call a remote-enabled function module that reveals non-sensitive ...

Jul 8, 2025
CVE-2025-24021
5.0

This vulnerability in iTop allows authenticated users with portal access to modify object fields they shouldn't have permission to change. It affects ...

May 14, 2025
CVE-2025-32684
5.0

This CVE describes a Missing Authorization vulnerability in the MapSVG Lite WordPress plugin that allows attackers to bypass access controls and perfo...

Apr 9, 2025
CVE-2023-24407
5.0

This CVE describes a missing authorization vulnerability in the WpDevArt Booking Calendar plugin for WordPress. It allows attackers to bypass access c...

Dec 9, 2024
CVE-2024-6631
5.0

The ImageRecycle WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify ...

Aug 24, 2024
CVE-2024-20355
5.0

This vulnerability allows authenticated remote attackers to bypass SAML authorization controls in Cisco ASA/FTD VPN services. Attackers can intercept ...

May 22, 2024
CVE-2024-0451
5.0

The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to list file...

May 22, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,061 CVEs classified as CWE-862, with 228 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free