CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,065
Total CVEs
230
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,065)

CVE-2025-14982
4.3

The Booking Calendar plugin for WordPress has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or hi...

Jan 16, 2026
CVE-2025-14384
4.3

The All in One SEO WordPress plugin has a missing capability check on its REST API endpoint, allowing authenticated users with Contributor-level acces...

Jan 16, 2026
CVE-2026-0635
4.3

The Responsive Accordion Slider WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or h...

Jan 14, 2026
CVE-2025-14482
4.3

The Crush.pics WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher to...

Jan 14, 2026
CVE-2025-13934
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to enroll themselves in any Tutor LMS course without pa...

Jan 9, 2026
CVE-2025-13935
4.3

The Tutor LMS WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to mar...

Jan 9, 2026
CVE-2025-13628
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to modify and delete coupon data in Tutor LMS. Attacker...

Jan 9, 2026
CVE-2026-22492
4.3

This CVE describes a Missing Authorization vulnerability in the Nawawi Jamili Docket Cache WordPress plugin that allows attackers to exploit incorrect...

Jan 8, 2026
CVE-2026-22487
4.3

CVE-2026-22487 is a missing authorization vulnerability in the baqend Speed Kit WordPress plugin, allowing attackers to bypass access controls and pot...

Jan 8, 2026
CVE-2026-0674
4.3

This CVE describes a missing authorization vulnerability in the Campaign Monitor for WordPress plugin that allows attackers to exploit incorrectly con...

Jan 8, 2026
CVE-2025-12640
4.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to replace arbitrary media files in the WordPress Medi...

Jan 8, 2026
CVE-2025-69333
4.3

CVE-2025-69333 is a missing authorization vulnerability in the Crocoblock JetEngine WordPress plugin that allows attackers to bypass intended access c...

Jan 7, 2026
CVE-2025-69344
4.3

A missing authorization vulnerability in the ThemeHunk Oneline Lite WordPress theme allows attackers to bypass access controls and potentially modify ...

Jan 7, 2026
CVE-2025-69355
4.3

This CVE describes a Missing Authorization vulnerability in the Tickera WordPress plugin that allows attackers to bypass access controls and perform u...

Jan 6, 2026
CVE-2025-69361
4.3

This vulnerability allows unauthorized users to modify Post Expirator plugin settings due to missing authorization checks. It affects WordPress sites ...

Jan 6, 2026
CVE-2025-69336
4.3

This CVE describes a Missing Authorization vulnerability in the Ultimate Store Kit Elementor Addons WordPress plugin that allows attackers to exploit ...

Jan 6, 2026
CVE-2025-69327
4.3

This CVE describes a missing authorization vulnerability in the Car Rental Manager WordPress plugin that allows attackers to bypass access controls. A...

Jan 6, 2026
CVE-2025-69331
4.3

This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass intended access controls....

Jan 6, 2026
CVE-2026-21429
4.3

This vulnerability in Emlog CMS allows administrators to restrict users from editing or deleting their own published articles. It affects all users of...

Jan 2, 2026
CVE-2025-63038
4.3

This vulnerability allows unauthorized users to access administrative functions in the WP Custom Admin Interface WordPress plugin due to missing autho...

Dec 31, 2025
CVE-2025-62874
4.3

This CVE describes a missing authorization vulnerability in the AnyComment WordPress plugin that allows attackers to bypass access controls. Attackers...

Dec 31, 2025
CVE-2025-62115
4.3

This CVE describes a Missing Authorization vulnerability in the ThemeBoy Hide Plugins WordPress plugin that allows attackers to bypass intended access...

Dec 31, 2025
CVE-2025-62078
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'Easy Upload Files During Checkout' that allows attackers to bypass a...

Dec 31, 2025
CVE-2025-62099
4.3

This CVE describes a missing authorization vulnerability in the Approveme Signature Add-On for Gravity Forms WordPress plugin. It allows attackers to ...

Dec 31, 2025
CVE-2025-49339
4.3

This CVE describes a Missing Authorization vulnerability in the Direct Payments WP WordPress plugin that allows attackers to bypass access controls. I...

Dec 31, 2025
CVE-2025-62751
4.3

A missing authorization vulnerability in the Extend Themes Vireo WordPress theme allows attackers to bypass intended access controls and potentially p...

Dec 31, 2025
CVE-2025-63004
4.3

This CVE describes a Missing Authorization vulnerability in Skynet Technologies USA LLC's All in One Accessibility WordPress plugin that allows attack...

Dec 31, 2025
CVE-2025-62150
4.3

This CVE describes a missing authorization vulnerability in the History Timeline WordPress plugin that allows attackers to bypass access controls. It ...

Dec 31, 2025
CVE-2025-62154
4.3

This CVE describes a Missing Authorization vulnerability in the Recorp AI Content Writing Assistant WordPress plugin that allows attackers to bypass a...

Dec 31, 2025
CVE-2025-62130
4.3

This CVE describes a Missing Authorization vulnerability in the WPdiscover Accordion Slider Gallery WordPress plugin that allows attackers to bypass i...

Dec 31, 2025
CVE-2025-62131
4.3

This CVE describes a Missing Authorization vulnerability in the Tasty Recipes Lite WordPress plugin that allows attackers to bypass access controls. I...

Dec 31, 2025
CVE-2025-62132
4.3

This CVE describes a Missing Authorization vulnerability in the Strategy11 Team Tasty Recipes Lite WordPress plugin that allows attackers to exploit i...

Dec 31, 2025
CVE-2025-62087
4.3

This CVE describes a missing authorization vulnerability in the Sticky Notes for WP Dashboard WordPress plugin. It allows attackers to exploit incorre...

Dec 31, 2025
CVE-2025-49356
4.3

This CVE describes a Missing Authorization vulnerability in the Orders Chat for WooCommerce WordPress plugin that allows attackers to bypass access co...

Dec 31, 2025
CVE-2024-58337
4.3

The Akuvox Smart Intercom S539 has an improper access control vulnerability that allows users with 'User' privileges to modify API settings and config...

Dec 30, 2025
CVE-2025-62128
4.3

This CVE describes a Missing Authorization vulnerability in the SiteLock Security WordPress plugin that allows attackers to bypass access controls. It...

Dec 30, 2025
CVE-2025-69091
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Demo Importer Plus plugin that allows attackers to exploit incorrectly confi...

Dec 30, 2025
CVE-2025-69023
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Discussion Board plugin (wp-discussion-board) that allows attackers to explo...

Dec 30, 2025
CVE-2025-69012
4.3

This CVE describes a Missing Authorization vulnerability in the Event Organiser WordPress plugin that allows attackers to exploit incorrectly configur...

Dec 30, 2025
CVE-2025-69013
4.3

This CVE describes a Missing Authorization vulnerability in the jetmonsters Stratum WordPress plugin that allows attackers to bypass access controls. ...

Dec 30, 2025
CVE-2025-69016
4.3

This vulnerability allows attackers to bypass authorization controls in the auxin-elements WordPress plugin, potentially accessing restricted function...

Dec 30, 2025
CVE-2025-68995
4.3

This CVE describes a Missing Authorization vulnerability in the My Sticky Elements WordPress plugin that allows attackers to exploit incorrectly confi...

Dec 30, 2025
CVE-2025-68557
4.3

This CVE describes a Missing Authorization vulnerability in the Vikas Ratudi Chakra test WordPress plugin that allows attackers to bypass access contr...

Dec 23, 2025
CVE-2023-25068
4.3

CVE-2023-25068 is a missing authorization vulnerability in the Magazine Edge WordPress theme that allows authenticated users to activate arbitrary plu...

Dec 21, 2025
CVE-2025-12361
4.3

This vulnerability in the myCred WordPress plugin allows authenticated attackers with Subscriber-level access or higher to retrieve sensitive user inf...

Dec 19, 2025
CVE-2025-7047
4.3

A missing authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows authenticated users to perform actions beyond their intended...

Dec 18, 2025
CVE-2025-14618
4.3

The Sweet Energy Efficiency WordPress plugin has an authorization vulnerability that allows authenticated users (even with low-privilege subscriber ac...

Dec 18, 2025
CVE-2025-13498
4.3

The Download Manager WordPress plugin up to version 3.3.32 has an authorization bypass vulnerability that allows authenticated users with Subscriber-l...

Dec 18, 2025
CVE-2025-13750
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete optimized WebP/AVIF image variants for any at...

Dec 17, 2025
CVE-2025-11369
4.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to view API keys configured for external services (Ins...

Dec 17, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,065 CVEs classified as CWE-862, with 230 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free