CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,067)
This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete optimized WebP/AVIF image variants for any at...
Dec 17, 2025This vulnerability allows authenticated WordPress users with Author-level permissions or higher to view API keys configured for external services (Ins...
Dec 17, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to retrieve email addresses of all users who can edit ...
Dec 16, 2025This CVE describes a missing authorization vulnerability in Codexert's Restrict Elementor Widgets WordPress plugin. It allows attackers to bypass inte...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WordPress 'Import external attachments' plugin that allows attackers to exploit incorr...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the Accessibility by AudioEye WordPress plugin that allows attackers to exploit incorrectl...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WordPress Request a Quote plugin that allows attackers to exploit incorrectly configur...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WPS Bidouille WordPress plugin that allows attackers to bypass access controls. It aff...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the WP Coupons and Deals WordPress plugin that allows attackers to bypass intended access ...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Easy Property Listings WordPress plugin that allows attackers to bypass access control...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the Directory Pro WordPress plugin that allows attackers to bypass access controls and per...
Dec 16, 2025This vulnerability allows unauthorized users to access administrative functions in the SKT Page Builder WordPress plugin due to missing authorization ...
Dec 16, 2025This CVE describes a Missing Authorization vulnerability in the CM On Demand Search And Replace WordPress plugin that allows attackers to exploit inco...
Dec 16, 2025This CVE describes a missing authorization vulnerability in the ThemeNectar Salient Core WordPress plugin that allows attackers to exploit incorrectly...
Dec 16, 2025The Auto Featured Image WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Contributor-level permissions ...
Dec 16, 2025This vulnerability allows authenticated WordPress users with Author-level permissions or higher to add images to Modula galleries owned by other users...
Dec 15, 2025This vulnerability allows authenticated WordPress users with author-level permissions or higher to create global folders and reassign arbitrary media ...
Dec 15, 2025The Userback WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to access sens...
Dec 13, 2025The Popover Windows WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or high...
Dec 13, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to modify plugin settings for the Gallery Blocks with ...
Dec 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to activate the Creativ Demo Importer plugin without pr...
Dec 13, 2025The Simple Theme Changer WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or...
Dec 12, 2025The URL Media Uploader WordPress plugin allows authenticated users with Contributor-level access or higher to upload safe media files without proper a...
Dec 12, 2025The Premmerce Brands for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access ...
Dec 12, 2025This vulnerability in Jenkins allows attackers with View/Read permission to view encrypted password values in views. It affects Jenkins 2.540 and earl...
Dec 10, 2025This CVE describes a missing authorization vulnerability in the ARMember WordPress plugin that allows attackers to bypass access controls. Attackers c...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Fluent Booking WordPress plugin that allows attackers to bypass access controls. It af...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in WebToffee's eCommerce Marketing Automation plugin for WooCommerce. It allows attackers to ...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the My Calendar WordPress plugin that allows attackers to exploit incorrectly configured a...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in Elementor Website Builder for WordPress that allows attackers to exploit incorrectly confi...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WooCommerce PDF Invoices & Packing Slips WordPress plugin that allows unauthorized use...
Dec 9, 2025A missing authorization vulnerability in the Ultimate Member ForumWP WordPress plugin allows attackers to bypass access controls and perform unauthori...
Dec 9, 2025This vulnerability allows unauthorized users to exploit broken access controls in the CRM Perks Integration plugin for WordPress. Attackers can potent...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Elastic Email Sender WordPress plugin that allows attackers to bypass access controls....
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Tablesome WordPress plugin that allows attackers to exploit incorrectly configured acc...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the VanKarWai Lobo WordPress theme that allows attackers to bypass access controls. It aff...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in Happy Addons for Elementor WordPress plugin that allows attackers to exploit incorrectly c...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the My Tickets WordPress plugin by Joe Dolson. It allows attackers to exploit incorrectly ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Porto Theme Functionality plugin for WordPress, allowing attackers to exploit incorrec...
Dec 9, 2025This vulnerability allows attackers to bypass authorization controls in the BestWebSoft Contact Form WordPress plugin, potentially accessing administr...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Xagio SEO WordPress plugin that allows attackers to exploit incorrectly configured acc...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Paysera WooCommerce Payment Gateway plugin that allows attackers to exploit incorrectl...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Custom Layouts plugin that allows attackers to exploit incorrectly configure...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the EventPrime WordPress plugin that allows attackers to bypass intended access controls. ...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Notification for Telegram plugin that allows attackers to bypass access cont...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the MultiParcels Shipping For WooCommerce WordPress plugin. It allows attackers to exploit...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Ergonet Cache WordPress plugin that allows attackers to bypass access controls. It aff...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Gravitec.net Web Push Notifications WordPress plugin that allows attackers to exploit ...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Image Cleanup WordPress plugin that allows attackers to exploit incorrectly configured...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Actionwear products sync WordPress plugin that allows attackers to exploit incorrectly...
Dec 9, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,067 CVEs classified as CWE-862, with 230 rated critical and 869 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free