CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,062
Total CVEs
229
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
438
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,062)

CVE-2024-0451
5.0

The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to list file...

May 22, 2024
CVE-2024-0453
5.0

The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to delete fi...

May 22, 2024
CVE-2025-64251
4.9

This CVE describes a Missing Authorization vulnerability in the Ultimate Learning Pro WordPress plugin (indeed-learning-pro) that allows attackers to ...

Dec 16, 2025
CVE-2025-60106
4.9

CVE-2025-60106 is a missing authorization vulnerability in the Roxnor EmailKit WordPress plugin that allows attackers to delete arbitrary content with...

Sep 26, 2025
CVE-2025-42949
4.9

This CVE describes an authorization bypass vulnerability in SAP ABAP Platform where authenticated users with elevated privileges can use the SQL Conso...

Aug 12, 2025
CVE-2025-30861
4.9

This CVE describes a missing authorization vulnerability in the Five Star Restaurant Reservations WordPress plugin that allows attackers to bypass acc...

Mar 27, 2025
CVE-2024-39823
4.9

This CVE describes a missing authorization vulnerability in Zoom Workplace components that could allow privileged users to access sensitive informatio...

Aug 14, 2024
CVE-2024-36113
4.9

This vulnerability allows a rogue staff user with administrative privileges in Discourse to suspend other staff users, preventing them from logging in...

Jul 3, 2024
CVE-2026-1787
4.8

The LearnPress Export Import WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete migrated cours...

Feb 21, 2026
CVE-2025-64249
4.8

This vulnerability allows attackers to bypass authorization controls in the Protect WP Admin WordPress plugin, potentially accessing restricted admini...

Dec 16, 2025
CVE-2025-12826
4.8

The Custom Post Type UI WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or hig...

Dec 4, 2025
CVE-2025-31606
4.8

This CVE describes a Missing Authorization vulnerability in the SP Blog Designer WordPress plugin that allows attackers to exploit incorrectly configu...

Mar 31, 2025
CVE-2025-27294
4.8

A missing authorization vulnerability in the WP-Asambleas WordPress plugin allows attackers to exploit incorrectly configured access controls. This en...

Feb 24, 2025
CVE-2024-11715
4.8

This vulnerability in the WP Job Portal WordPress plugin allows unauthenticated attackers to assign themselves the employer role without proper author...

Dec 14, 2024
CVE-2025-64630
4.7

This CVE describes a missing authorization vulnerability in the Strategy11 Team Business Directory WordPress plugin that allows attackers to exploit i...

Dec 16, 2025
CVE-2025-48614
4.6

This vulnerability allows unauthorized factory resets of Android devices running in Dynamic System Updates (DSU) mode due to a missing permission chec...

Dec 8, 2025
CVE-2024-54470
4.6

This CVE describes a lock screen bypass vulnerability in Apple iOS and iPadOS that allows an attacker with physical access to view contacts without au...

Jan 15, 2025
CVE-2025-24116
4.4

This CVE describes a macOS sandbox bypass vulnerability that allows applications to circumvent Privacy preferences. It affects macOS Ventura, Sequoia,...

Jan 27, 2025
CVE-2026-30842
4.3

CVE-2026-30842 is an authorization bypass vulnerability in Wallos that allows authenticated users to delete avatar files uploaded by other users. The ...

Mar 7, 2026
CVE-2026-3056
4.3

The Seraphinite Accelerator WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher...

Mar 4, 2026
CVE-2026-28555
4.3

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wp...

Feb 28, 2026
CVE-2025-14103
4.3

This vulnerability allows unauthorized users with Developer-role permissions to set pipeline variables for manually triggered jobs in GitLab. This aff...

Feb 25, 2026
CVE-2026-28195
4.3

This CVE describes a missing authorization vulnerability in JetBrains TeamCity where project developers can add parameters to build configurations wit...

Feb 25, 2026
CVE-2026-2301
4.3

The Post Duplicator WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject arbitrary protected post meta ke...

Feb 25, 2026
CVE-2024-54222
4.3

This CVE describes a Missing Authorization vulnerability in the Seraphinite Accelerator WordPress plugin that allows authenticated users to retrieve e...

Feb 20, 2026
CVE-2026-27327
4.3

This CVE describes a Missing Authorization vulnerability in the YayMail WooCommerce Email Customizer WordPress plugin that allows attackers to exploit...

Feb 19, 2026
CVE-2026-27055
4.3

This CVE describes a Missing Authorization vulnerability in the Penci AI SmartContent Creator WordPress plugin that allows attackers to bypass access ...

Feb 19, 2026
CVE-2026-25459
4.3

This CVE describes a Missing Authorization vulnerability in the Sober WordPress theme that allows attackers to bypass access controls. It affects all ...

Feb 19, 2026
CVE-2026-25420
4.3

This CVE describes a Missing Authorization vulnerability in the MailerLite WordPress plugin that allows attackers to exploit incorrectly configured ac...

Feb 19, 2026
CVE-2026-25402
4.3

This CVE describes a Missing Authorization vulnerability in the Echo Knowledge Base WordPress plugin that allows attackers to bypass access controls. ...

Feb 19, 2026
CVE-2026-25407
4.3

This CVE describes a Missing Authorization vulnerability in the Cookiebot WordPress plugin that allows attackers to exploit incorrectly configured acc...

Feb 19, 2026
CVE-2026-25409
4.3

This CVE describes a Missing Authorization vulnerability in the JAMstack Deployments WordPress plugin that allows attackers to exploit incorrectly con...

Feb 19, 2026
CVE-2026-25393
4.3

This CVE describes a Missing Authorization vulnerability in the Hello FSE WordPress theme that allows attackers to exploit incorrectly configured acce...

Feb 19, 2026
CVE-2026-25395
4.3

This CVE describes a missing authorization vulnerability in the Business Roy WordPress theme that allows attackers to bypass access controls. It affec...

Feb 19, 2026
CVE-2026-25375
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Final Tiles Grid Gallery Lite plugin that allows attackers to bypass access ...

Feb 19, 2026
CVE-2026-25335
4.3

This CVE describes a missing authorization vulnerability in the Ays Pro Secure Copy Content Protection and Content Locking WordPress plugin. It allows...

Feb 19, 2026
CVE-2026-25330
4.3

This CVE describes a Missing Authorization vulnerability in the PublishPress Authors WordPress plugin that allows attackers to exploit incorrectly con...

Feb 19, 2026
CVE-2026-25318
4.3

This CVE describes a Missing Authorization vulnerability in the WiserReview Product Reviews for WooCommerce WordPress plugin. It allows attackers to e...

Feb 19, 2026
CVE-2026-25313
4.3

This CVE describes a missing authorization vulnerability in the FluentForm WordPress plugin that allows attackers to bypass access controls. It affect...

Feb 19, 2026
CVE-2026-25003
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Client Portal plugin that allows attackers to bypass access controls. It aff...

Feb 19, 2026
CVE-2026-2504
4.3

The Dealia WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level permissions or higher to ...

Feb 19, 2026
CVE-2025-14864
4.3

The Virusdie WordPress plugin exposes API keys to authenticated users with Subscriber-level access or higher due to missing capability checks. This al...

Feb 19, 2026
CVE-2025-12081
4.3

The ACF Photo Gallery Field plugin for WordPress has a missing capability check that allows authenticated users with subscriber-level access or higher...

Feb 19, 2026
CVE-2026-1860
4.3

The Kali Forms WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated users with Contributor-level access or...

Feb 18, 2026
CVE-2026-1655
4.3

The EventPrime WordPress plugin allows authenticated attackers with Customer+ roles to modify administrator-created event posts without authorization....

Feb 18, 2026
CVE-2026-1640
4.3

The Taskbuilder WordPress plugin has an authorization bypass vulnerability that allows authenticated users (subscriber level or higher) to post commen...

Feb 18, 2026
CVE-2025-12356
4.3

The Tickera WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher to modif...

Feb 18, 2026
CVE-2026-2608
4.3

This vulnerability in the Kadence Blocks WordPress plugin allows authenticated users with Contributor-level access or higher to perform unauthorized a...

Feb 17, 2026
CVE-2025-14350
4.3

This vulnerability allows authenticated Mattermost users to discover the existence of teams and their URL names by posting channel shortlinks and obse...

Feb 16, 2026
CVE-2026-0929
4.3

The RegistrationMagic WordPress plugin before version 6.0.7.2 lacks proper capability checks, allowing users with subscriber-level permissions or high...

Feb 16, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,062 CVEs classified as CWE-862, with 229 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free