CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,065)
The Booking Calendar plugin for WordPress has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or hi...
Jan 16, 2026The All in One SEO WordPress plugin has a missing capability check on its REST API endpoint, allowing authenticated users with Contributor-level acces...
Jan 16, 2026The Responsive Accordion Slider WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or h...
Jan 14, 2026The Crush.pics WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher to...
Jan 14, 2026This vulnerability allows authenticated WordPress users with subscriber-level access or higher to enroll themselves in any Tutor LMS course without pa...
Jan 9, 2026The Tutor LMS WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to mar...
Jan 9, 2026This vulnerability allows authenticated WordPress users with subscriber-level access or higher to modify and delete coupon data in Tutor LMS. Attacker...
Jan 9, 2026This CVE describes a Missing Authorization vulnerability in the Nawawi Jamili Docket Cache WordPress plugin that allows attackers to exploit incorrect...
Jan 8, 2026CVE-2026-22487 is a missing authorization vulnerability in the baqend Speed Kit WordPress plugin, allowing attackers to bypass access controls and pot...
Jan 8, 2026This CVE describes a missing authorization vulnerability in the Campaign Monitor for WordPress plugin that allows attackers to exploit incorrectly con...
Jan 8, 2026This vulnerability allows authenticated WordPress users with Author-level permissions or higher to replace arbitrary media files in the WordPress Medi...
Jan 8, 2026CVE-2025-69333 is a missing authorization vulnerability in the Crocoblock JetEngine WordPress plugin that allows attackers to bypass intended access c...
Jan 7, 2026A missing authorization vulnerability in the ThemeHunk Oneline Lite WordPress theme allows attackers to bypass access controls and potentially modify ...
Jan 7, 2026This CVE describes a Missing Authorization vulnerability in the Tickera WordPress plugin that allows attackers to bypass access controls and perform u...
Jan 6, 2026This vulnerability allows unauthorized users to modify Post Expirator plugin settings due to missing authorization checks. It affects WordPress sites ...
Jan 6, 2026This CVE describes a Missing Authorization vulnerability in the Ultimate Store Kit Elementor Addons WordPress plugin that allows attackers to exploit ...
Jan 6, 2026This CVE describes a missing authorization vulnerability in the Car Rental Manager WordPress plugin that allows attackers to bypass access controls. A...
Jan 6, 2026This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass intended access controls....
Jan 6, 2026This vulnerability in Emlog CMS allows administrators to restrict users from editing or deleting their own published articles. It affects all users of...
Jan 2, 2026This vulnerability allows unauthorized users to access administrative functions in the WP Custom Admin Interface WordPress plugin due to missing autho...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the AnyComment WordPress plugin that allows attackers to bypass access controls. Attackers...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the ThemeBoy Hide Plugins WordPress plugin that allows attackers to bypass intended access...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'Easy Upload Files During Checkout' that allows attackers to bypass a...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the Approveme Signature Add-On for Gravity Forms WordPress plugin. It allows attackers to ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Direct Payments WP WordPress plugin that allows attackers to bypass access controls. I...
Dec 31, 2025A missing authorization vulnerability in the Extend Themes Vireo WordPress theme allows attackers to bypass intended access controls and potentially p...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in Skynet Technologies USA LLC's All in One Accessibility WordPress plugin that allows attack...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the History Timeline WordPress plugin that allows attackers to bypass access controls. It ...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Recorp AI Content Writing Assistant WordPress plugin that allows attackers to bypass a...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the WPdiscover Accordion Slider Gallery WordPress plugin that allows attackers to bypass i...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Tasty Recipes Lite WordPress plugin that allows attackers to bypass access controls. I...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Strategy11 Team Tasty Recipes Lite WordPress plugin that allows attackers to exploit i...
Dec 31, 2025This CVE describes a missing authorization vulnerability in the Sticky Notes for WP Dashboard WordPress plugin. It allows attackers to exploit incorre...
Dec 31, 2025This CVE describes a Missing Authorization vulnerability in the Orders Chat for WooCommerce WordPress plugin that allows attackers to bypass access co...
Dec 31, 2025The Akuvox Smart Intercom S539 has an improper access control vulnerability that allows users with 'User' privileges to modify API settings and config...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the SiteLock Security WordPress plugin that allows attackers to bypass access controls. It...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Demo Importer Plus plugin that allows attackers to exploit incorrectly confi...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Discussion Board plugin (wp-discussion-board) that allows attackers to explo...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Event Organiser WordPress plugin that allows attackers to exploit incorrectly configur...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the jetmonsters Stratum WordPress plugin that allows attackers to bypass access controls. ...
Dec 30, 2025This vulnerability allows attackers to bypass authorization controls in the auxin-elements WordPress plugin, potentially accessing restricted function...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the My Sticky Elements WordPress plugin that allows attackers to exploit incorrectly confi...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the Vikas Ratudi Chakra test WordPress plugin that allows attackers to bypass access contr...
Dec 23, 2025CVE-2023-25068 is a missing authorization vulnerability in the Magazine Edge WordPress theme that allows authenticated users to activate arbitrary plu...
Dec 21, 2025This vulnerability in the myCred WordPress plugin allows authenticated attackers with Subscriber-level access or higher to retrieve sensitive user inf...
Dec 19, 2025A missing authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows authenticated users to perform actions beyond their intended...
Dec 18, 2025The Sweet Energy Efficiency WordPress plugin has an authorization vulnerability that allows authenticated users (even with low-privilege subscriber ac...
Dec 18, 2025The Download Manager WordPress plugin up to version 3.3.32 has an authorization bypass vulnerability that allows authenticated users with Subscriber-l...
Dec 18, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete optimized WebP/AVIF image variants for any at...
Dec 17, 2025This vulnerability allows authenticated WordPress users with Author-level permissions or higher to view API keys configured for external services (Ins...
Dec 17, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,065 CVEs classified as CWE-862, with 230 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free