CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,068)
This CVE describes a Missing Authorization vulnerability in the Actionwear products sync WordPress plugin that allows attackers to exploit incorrectly...
Dec 9, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify listing details without proper authorization....
Dec 6, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary posts through a REST API endpoint. ...
Dec 6, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to deactivate the Search, Filters & Merchandising for W...
Dec 6, 2025The Beaver Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with contributor-level access or higher ...
Dec 4, 2025The Fluent Booking WordPress plugin has an authorization vulnerability that allows any authenticated user (including subscribers) to import and manage...
Dec 3, 2025This vulnerability allows authenticated WordPress users with subscriber-level access or higher to merge or delete arbitrary taxonomy terms without pro...
Dec 3, 2025The Beaver Builder WordPress plugin has a missing authorization vulnerability that allows authenticated users with contributor-level access or higher ...
Dec 2, 2025The WP Fastest Cache WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher...
Nov 27, 2025This vulnerability in the Refund Request for WooCommerce WordPress plugin allows authenticated users with Subscriber-level access or higher to modify ...
Nov 25, 2025The Search Exclude WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or higher to modi...
Nov 25, 2025This CVE describes a Missing Authorization vulnerability in the TNC Toolbox: Web Performance WordPress plugin that allows attackers to exploit incorre...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the WebToffee Accessibility Toolkit WordPress plugin that allows attackers to bypass acces...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the Table Block by Tableberg WordPress plugin that allows attackers to exploit incorrectly...
Nov 21, 2025This vulnerability allows unauthorized users to access bookmark management functions in the CBX Bookmark & Favorite WordPress plugin due to missing au...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the WordPress Featured Post Creative plugin that allows attackers to bypass access control...
Nov 21, 2025This vulnerability allows unauthorized users to access functionality intended only for authenticated administrators in the WebToffee Product Feed for ...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the WpEvently mage-eventpress WordPress plugin that allows attackers to exploit incorrectl...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the WpEvently mage-eventpress WordPress plugin that allows attackers to bypass access cont...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the FluentCommunity WordPress plugin that allows attackers to exploit incorrectly configur...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the Arconix Shortcodes WordPress plugin that allows attackers to exploit incorrectly confi...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the Legal Pages WordPress plugin that allows attackers to bypass access controls and perfo...
Nov 21, 2025This CVE describes a missing authorization vulnerability in the PPOM for WooCommerce plugin that allows attackers to bypass access controls and perfor...
Nov 21, 2025This vulnerability allows authenticated WordPress users with author-level permissions or higher to modify arbitrary posts and pages via a REST API end...
Nov 21, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify smart contract addresses displayed by the Tok...
Nov 21, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to clear scheduled triggers in the ELEX HelpDesk plugin...
Nov 21, 2025The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to restor...
Nov 21, 2025The ELEX WordPress HelpDesk plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher to...
Nov 21, 2025The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to perman...
Nov 21, 2025The WSChat WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to reset plugin ...
Nov 19, 2025The wModes WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to access...
Nov 18, 2025The WP Duplicate Page WordPress plugin has a missing authorization vulnerability that allows authenticated users with Contributor-level access or high...
Nov 18, 2025The Download Panel WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify pl...
Nov 18, 2025The Permalinks Cascade WordPress plugin has a missing authorization vulnerability that allows authenticated users with subscriber-level access or high...
Nov 18, 2025The Envira Photo Gallery WordPress plugin has an authorization vulnerability that allows authenticated users with Author-level permissions or higher t...
Nov 13, 2025This CVE describes a Missing Authorization vulnerability in the WebToffee Order Export & Order Import for WooCommerce plugin that allows attackers to ...
Nov 13, 2025This CVE describes a missing authorization vulnerability in the Pluggabl Booster for WooCommerce plugin that allows attackers to exploit incorrectly c...
Nov 13, 2025This CVE describes a missing authorization vulnerability in the WooCommerce PDF Invoice Builder WordPress plugin that allows unauthorized users to acc...
Nov 13, 2025This CVE describes a Missing Authorization vulnerability in the WPKoi Templates for Elementor WordPress plugin that allows attackers to exploit incorr...
Nov 13, 2025This CVE describes a Missing Authorization vulnerability in the N-Media Frontend File Manager WordPress plugin (nmedia-user-file-uploader). It allows ...
Nov 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to disconnect the Afosto service from the Quicq plugin ...
Nov 13, 2025This vulnerability in the Alt Text Generator AI WordPress plugin allows authenticated attackers with Subscriber-level access or higher to delete the A...
Nov 12, 2025This vulnerability allows authenticated WordPress users with subscriber-level access or higher to add, update, or delete listing types in the Classifi...
Nov 11, 2025CVE-2025-42899 is an authorization bypass vulnerability in SAP S4CORE's Manage Journal Entries function that allows authenticated users to perform una...
Nov 11, 2025This vulnerability allows authenticated attackers with basic privileges in SAP NetWeaver Application Server for ABAP to execute a specific function mo...
Nov 11, 2025This vulnerability allows authenticated users with Service Desk Agent permissions in Combodo iTop to create ModuleInstallation objects without proper ...
Nov 10, 2025This CVE describes a missing authorization vulnerability in the rymcu forest software's BankController component. Attackers can remotely exploit this ...
Nov 10, 2025The Envira Photo Gallery WordPress plugin has a missing capability check on its bulk-convert REST API endpoint, allowing authenticated users with cont...
Nov 8, 2025The EventPrime WordPress plugin allows authenticated users with Subscriber-level access or higher to add notes to any booking in the backend without p...
Nov 8, 2025The Contact Form 7 AWeber Extension plugin for WordPress has an authorization vulnerability that allows authenticated users with Subscriber-level acce...
Nov 8, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,068 CVEs classified as CWE-862, with 230 rated critical and 870 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free