CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,062)
The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to list file...
May 22, 2024The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to delete fi...
May 22, 2024This CVE describes a Missing Authorization vulnerability in the Ultimate Learning Pro WordPress plugin (indeed-learning-pro) that allows attackers to ...
Dec 16, 2025CVE-2025-60106 is a missing authorization vulnerability in the Roxnor EmailKit WordPress plugin that allows attackers to delete arbitrary content with...
Sep 26, 2025This CVE describes an authorization bypass vulnerability in SAP ABAP Platform where authenticated users with elevated privileges can use the SQL Conso...
Aug 12, 2025This CVE describes a missing authorization vulnerability in the Five Star Restaurant Reservations WordPress plugin that allows attackers to bypass acc...
Mar 27, 2025This CVE describes a missing authorization vulnerability in Zoom Workplace components that could allow privileged users to access sensitive informatio...
Aug 14, 2024This vulnerability allows a rogue staff user with administrative privileges in Discourse to suspend other staff users, preventing them from logging in...
Jul 3, 2024The LearnPress Export Import WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete migrated cours...
Feb 21, 2026This vulnerability allows attackers to bypass authorization controls in the Protect WP Admin WordPress plugin, potentially accessing restricted admini...
Dec 16, 2025The Custom Post Type UI WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or hig...
Dec 4, 2025This CVE describes a Missing Authorization vulnerability in the SP Blog Designer WordPress plugin that allows attackers to exploit incorrectly configu...
Mar 31, 2025A missing authorization vulnerability in the WP-Asambleas WordPress plugin allows attackers to exploit incorrectly configured access controls. This en...
Feb 24, 2025This vulnerability in the WP Job Portal WordPress plugin allows unauthenticated attackers to assign themselves the employer role without proper author...
Dec 14, 2024This CVE describes a missing authorization vulnerability in the Strategy11 Team Business Directory WordPress plugin that allows attackers to exploit i...
Dec 16, 2025This vulnerability allows unauthorized factory resets of Android devices running in Dynamic System Updates (DSU) mode due to a missing permission chec...
Dec 8, 2025This CVE describes a lock screen bypass vulnerability in Apple iOS and iPadOS that allows an attacker with physical access to view contacts without au...
Jan 15, 2025This CVE describes a macOS sandbox bypass vulnerability that allows applications to circumvent Privacy preferences. It affects macOS Ventura, Sequoia,...
Jan 27, 2025CVE-2026-30842 is an authorization bypass vulnerability in Wallos that allows authenticated users to delete avatar files uploaded by other users. The ...
Mar 7, 2026The Seraphinite Accelerator WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher...
Mar 4, 2026wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wp...
Feb 28, 2026This vulnerability allows unauthorized users with Developer-role permissions to set pipeline variables for manually triggered jobs in GitLab. This aff...
Feb 25, 2026This CVE describes a missing authorization vulnerability in JetBrains TeamCity where project developers can add parameters to build configurations wit...
Feb 25, 2026The Post Duplicator WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject arbitrary protected post meta ke...
Feb 25, 2026This CVE describes a Missing Authorization vulnerability in the Seraphinite Accelerator WordPress plugin that allows authenticated users to retrieve e...
Feb 20, 2026This CVE describes a Missing Authorization vulnerability in the YayMail WooCommerce Email Customizer WordPress plugin that allows attackers to exploit...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the Penci AI SmartContent Creator WordPress plugin that allows attackers to bypass access ...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the Sober WordPress theme that allows attackers to bypass access controls. It affects all ...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the MailerLite WordPress plugin that allows attackers to exploit incorrectly configured ac...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the Echo Knowledge Base WordPress plugin that allows attackers to bypass access controls. ...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the Cookiebot WordPress plugin that allows attackers to exploit incorrectly configured acc...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the JAMstack Deployments WordPress plugin that allows attackers to exploit incorrectly con...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the Hello FSE WordPress theme that allows attackers to exploit incorrectly configured acce...
Feb 19, 2026This CVE describes a missing authorization vulnerability in the Business Roy WordPress theme that allows attackers to bypass access controls. It affec...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the WordPress Final Tiles Grid Gallery Lite plugin that allows attackers to bypass access ...
Feb 19, 2026This CVE describes a missing authorization vulnerability in the Ays Pro Secure Copy Content Protection and Content Locking WordPress plugin. It allows...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the PublishPress Authors WordPress plugin that allows attackers to exploit incorrectly con...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the WiserReview Product Reviews for WooCommerce WordPress plugin. It allows attackers to e...
Feb 19, 2026This CVE describes a missing authorization vulnerability in the FluentForm WordPress plugin that allows attackers to bypass access controls. It affect...
Feb 19, 2026This CVE describes a Missing Authorization vulnerability in the WordPress Client Portal plugin that allows attackers to bypass access controls. It aff...
Feb 19, 2026The Dealia WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level permissions or higher to ...
Feb 19, 2026The Virusdie WordPress plugin exposes API keys to authenticated users with Subscriber-level access or higher due to missing capability checks. This al...
Feb 19, 2026The ACF Photo Gallery Field plugin for WordPress has a missing capability check that allows authenticated users with subscriber-level access or higher...
Feb 19, 2026The Kali Forms WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated users with Contributor-level access or...
Feb 18, 2026The EventPrime WordPress plugin allows authenticated attackers with Customer+ roles to modify administrator-created event posts without authorization....
Feb 18, 2026The Taskbuilder WordPress plugin has an authorization bypass vulnerability that allows authenticated users (subscriber level or higher) to post commen...
Feb 18, 2026The Tickera WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher to modif...
Feb 18, 2026This vulnerability in the Kadence Blocks WordPress plugin allows authenticated users with Contributor-level access or higher to perform unauthorized a...
Feb 17, 2026This vulnerability allows authenticated Mattermost users to discover the existence of teams and their URL names by posting channel shortlinks and obse...
Feb 16, 2026The RegistrationMagic WordPress plugin before version 6.0.7.2 lacks proper capability checks, allowing users with subscriber-level permissions or high...
Feb 16, 2026About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,062 CVEs classified as CWE-862, with 229 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free