CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,067
Total CVEs
230
Critical
869
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 37
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,067)

CVE-2025-13750
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete optimized WebP/AVIF image variants for any at...

Dec 17, 2025
CVE-2025-11369
4.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to view API keys configured for external services (Ins...

Dec 17, 2025
CVE-2025-13741
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to retrieve email addresses of all users who can edit ...

Dec 16, 2025
CVE-2025-64244
4.3

This CVE describes a missing authorization vulnerability in Codexert's Restrict Elementor Widgets WordPress plugin. It allows attackers to bypass inte...

Dec 16, 2025
CVE-2025-64245
4.3

This CVE describes a missing authorization vulnerability in the WordPress 'Import external attachments' plugin that allows attackers to exploit incorr...

Dec 16, 2025
CVE-2025-64246
4.3

This CVE describes a Missing Authorization vulnerability in the Accessibility by AudioEye WordPress plugin that allows attackers to exploit incorrectl...

Dec 16, 2025
CVE-2025-64248
4.3

This CVE describes a missing authorization vulnerability in the WordPress Request a Quote plugin that allows attackers to exploit incorrectly configur...

Dec 16, 2025
CVE-2025-64238
4.3

This CVE describes a missing authorization vulnerability in the WPS Bidouille WordPress plugin that allows attackers to bypass access controls. It aff...

Dec 16, 2025
CVE-2025-64241
4.3

This CVE describes a missing authorization vulnerability in the WP Coupons and Deals WordPress plugin that allows attackers to bypass intended access ...

Dec 16, 2025
CVE-2025-64242
4.3

This CVE describes a missing authorization vulnerability in the Easy Property Listings WordPress plugin that allows attackers to bypass access control...

Dec 16, 2025
CVE-2025-64243
4.3

This CVE describes a missing authorization vulnerability in the Directory Pro WordPress plugin that allows attackers to bypass access controls and per...

Dec 16, 2025
CVE-2025-54005
4.3

This vulnerability allows unauthorized users to access administrative functions in the SKT Page Builder WordPress plugin due to missing authorization ...

Dec 16, 2025
CVE-2025-54045
4.3

This CVE describes a Missing Authorization vulnerability in the CM On Demand Search And Replace WordPress plugin that allows attackers to exploit inco...

Dec 16, 2025
CVE-2025-59001
4.3

This CVE describes a missing authorization vulnerability in the ThemeNectar Salient Core WordPress plugin that allows attackers to exploit incorrectly...

Dec 16, 2025
CVE-2025-13794
4.3

The Auto Featured Image WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level permissions ...

Dec 16, 2025
CVE-2025-14003
4.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to add images to Modula galleries owned by other users...

Dec 15, 2025
CVE-2025-12900
4.3

This vulnerability allows authenticated WordPress users with author-level permissions or higher to create global folders and reassign arbitrary media ...

Dec 15, 2025
CVE-2025-14540
4.3

The Userback WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to access sens...

Dec 13, 2025
CVE-2025-14395
4.3

The Popover Windows WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or high...

Dec 13, 2025
CVE-2025-14288
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to modify plugin settings for the Gallery Blocks with ...

Dec 13, 2025
CVE-2025-11164
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to activate the Creativ Demo Importer plugin without pr...

Dec 13, 2025
CVE-2025-14392
4.3

The Simple Theme Changer WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or...

Dec 12, 2025
CVE-2025-14045
4.3

The URL Media Uploader WordPress plugin allows authenticated users with Contributor-level access or higher to upload safe media files without proper a...

Dec 12, 2025
CVE-2025-12783
4.3

The Premmerce Brands for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access ...

Dec 12, 2025
CVE-2025-67636
4.3

This vulnerability in Jenkins allows attackers with View/Read permission to view encrypted password values in views. It affects Jenkins 2.540 and earl...

Dec 10, 2025
CVE-2022-47425
4.3

This CVE describes a missing authorization vulnerability in the ARMember WordPress plugin that allows attackers to bypass access controls. Attackers c...

Dec 9, 2025
CVE-2025-67597
4.3

This CVE describes a missing authorization vulnerability in the Fluent Booking WordPress plugin that allows attackers to bypass access controls. It af...

Dec 9, 2025
CVE-2025-67599
4.3

This CVE describes a Missing Authorization vulnerability in WebToffee's eCommerce Marketing Automation plugin for WooCommerce. It allows attackers to ...

Dec 9, 2025
CVE-2025-67592
4.3

This CVE describes a Missing Authorization vulnerability in the My Calendar WordPress plugin that allows attackers to exploit incorrectly configured a...

Dec 9, 2025
CVE-2025-67588
4.3

This CVE describes a Missing Authorization vulnerability in Elementor Website Builder for WordPress that allows attackers to exploit incorrectly confi...

Dec 9, 2025
CVE-2025-67589
4.3

This CVE describes a missing authorization vulnerability in the WooCommerce PDF Invoices & Packing Slips WordPress plugin that allows unauthorized use...

Dec 9, 2025
CVE-2025-67474
4.3

A missing authorization vulnerability in the Ultimate Member ForumWP WordPress plugin allows attackers to bypass access controls and perform unauthori...

Dec 9, 2025
CVE-2025-67468
4.3

This vulnerability allows unauthorized users to exploit broken access controls in the CRM Perks Integration plugin for WordPress. Attackers can potent...

Dec 9, 2025
CVE-2025-66525
4.3

This CVE describes a Missing Authorization vulnerability in the Elastic Email Sender WordPress plugin that allows attackers to bypass access controls....

Dec 9, 2025
CVE-2025-66526
4.3

This CVE describes a Missing Authorization vulnerability in the Tablesome WordPress plugin that allows attackers to exploit incorrectly configured acc...

Dec 9, 2025
CVE-2025-66527
4.3

This CVE describes a missing authorization vulnerability in the VanKarWai Lobo WordPress theme that allows attackers to bypass access controls. It aff...

Dec 9, 2025
CVE-2025-63077
4.3

This CVE describes a Missing Authorization vulnerability in Happy Addons for Elementor WordPress plugin that allows attackers to exploit incorrectly c...

Dec 9, 2025
CVE-2025-64257
4.3

This CVE describes a Missing Authorization vulnerability in the My Tickets WordPress plugin by Joe Dolson. It allows attackers to exploit incorrectly ...

Dec 9, 2025
CVE-2025-63067
4.3

This CVE describes a missing authorization vulnerability in the Porto Theme Functionality plugin for WordPress, allowing attackers to exploit incorrec...

Dec 9, 2025
CVE-2025-63056
4.3

This vulnerability allows attackers to bypass authorization controls in the BestWebSoft Contact Form WordPress plugin, potentially accessing administr...

Dec 9, 2025
CVE-2025-63025
4.3

This CVE describes a missing authorization vulnerability in the Xagio SEO WordPress plugin that allows attackers to exploit incorrectly configured acc...

Dec 9, 2025
CVE-2025-63015
4.3

This CVE describes a Missing Authorization vulnerability in the Paysera WooCommerce Payment Gateway plugin that allows attackers to exploit incorrectl...

Dec 9, 2025
CVE-2025-62996
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Custom Layouts plugin that allows attackers to exploit incorrectly configure...

Dec 9, 2025
CVE-2025-63006
4.3

This CVE describes a Missing Authorization vulnerability in the EventPrime WordPress plugin that allows attackers to bypass intended access controls. ...

Dec 9, 2025
CVE-2025-62993
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Notification for Telegram plugin that allows attackers to bypass access cont...

Dec 9, 2025
CVE-2025-62995
4.3

This CVE describes a Missing Authorization vulnerability in the MultiParcels Shipping For WooCommerce WordPress plugin. It allows attackers to exploit...

Dec 9, 2025
CVE-2025-62867
4.3

This CVE describes a missing authorization vulnerability in the Ergonet Cache WordPress plugin that allows attackers to bypass access controls. It aff...

Dec 9, 2025
CVE-2025-62869
4.3

This CVE describes a Missing Authorization vulnerability in the Gravitec.net Web Push Notifications WordPress plugin that allows attackers to exploit ...

Dec 9, 2025
CVE-2025-62736
4.3

This CVE describes a missing authorization vulnerability in the Image Cleanup WordPress plugin that allows attackers to exploit incorrectly configured...

Dec 9, 2025
CVE-2025-49350
4.3

This CVE describes a Missing Authorization vulnerability in the Actionwear products sync WordPress plugin that allows attackers to exploit incorrectly...

Dec 9, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,067 CVEs classified as CWE-862, with 230 rated critical and 869 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free