CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,068
Total CVEs
230
Critical
870
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 37
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,068)

CVE-2025-49350
4.3

This CVE describes a Missing Authorization vulnerability in the Actionwear products sync WordPress plugin that allows attackers to exploit incorrectly...

Dec 9, 2025
CVE-2025-12577
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify listing details without proper authorization....

Dec 6, 2025
CVE-2025-12574
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary posts through a REST API endpoint. ...

Dec 6, 2025
CVE-2025-12091
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to deactivate the Search, Filters & Merchandising for W...

Dec 6, 2025
CVE-2025-12782
4.3

The Beaver Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with contributor-level access or higher ...

Dec 4, 2025
CVE-2025-13756
4.3

The Fluent Booking WordPress plugin has an authorization vulnerability that allows any authenticated user (including subscribers) to import and manage...

Dec 3, 2025
CVE-2025-13354
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to merge or delete arbitrary taxonomy terms without pro...

Dec 3, 2025
CVE-2025-11726
4.3

The Beaver Builder WordPress plugin has a missing authorization vulnerability that allows authenticated users with contributor-level access or higher ...

Dec 2, 2025
CVE-2025-10476
4.3

The WP Fastest Cache WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher...

Nov 27, 2025
CVE-2025-12634
4.3

This vulnerability in the Refund Request for WooCommerce WordPress plugin allows authenticated users with Subscriber-level access or higher to modify ...

Nov 25, 2025
CVE-2025-10646
4.3

The Search Exclude WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or higher to modi...

Nov 25, 2025
CVE-2025-66108
4.3

This CVE describes a Missing Authorization vulnerability in the TNC Toolbox: Web Performance WordPress plugin that allows attackers to exploit incorre...

Nov 21, 2025
CVE-2025-66112
4.3

This CVE describes a Missing Authorization vulnerability in the WebToffee Accessibility Toolkit WordPress plugin that allows attackers to bypass acces...

Nov 21, 2025
CVE-2025-66096
4.3

This CVE describes a missing authorization vulnerability in the Table Block by Tableberg WordPress plugin that allows attackers to exploit incorrectly...

Nov 21, 2025
CVE-2025-66101
4.3

This vulnerability allows unauthorized users to access bookmark management functions in the CBX Bookmark & Favorite WordPress plugin due to missing au...

Nov 21, 2025
CVE-2025-66106
4.3

This CVE describes a missing authorization vulnerability in the WordPress Featured Post Creative plugin that allows attackers to bypass access control...

Nov 21, 2025
CVE-2025-66089
4.3

This vulnerability allows unauthorized users to access functionality intended only for authenticated administrators in the WebToffee Product Feed for ...

Nov 21, 2025
CVE-2025-66082
4.3

This CVE describes a Missing Authorization vulnerability in the WpEvently mage-eventpress WordPress plugin that allows attackers to exploit incorrectl...

Nov 21, 2025
CVE-2025-66083
4.3

This CVE describes a missing authorization vulnerability in the WpEvently mage-eventpress WordPress plugin that allows attackers to bypass access cont...

Nov 21, 2025
CVE-2025-66084
4.3

This CVE describes a Missing Authorization vulnerability in the FluentCommunity WordPress plugin that allows attackers to exploit incorrectly configur...

Nov 21, 2025
CVE-2025-66085
4.3

This CVE describes a Missing Authorization vulnerability in the Arconix Shortcodes WordPress plugin that allows attackers to exploit incorrectly confi...

Nov 21, 2025
CVE-2025-66077
4.3

This CVE describes a Missing Authorization vulnerability in the Legal Pages WordPress plugin that allows attackers to bypass access controls and perfo...

Nov 21, 2025
CVE-2025-66069
4.3

This CVE describes a missing authorization vulnerability in the PPOM for WooCommerce plugin that allows attackers to bypass access controls and perfor...

Nov 21, 2025
CVE-2025-13149
4.3

This vulnerability allows authenticated WordPress users with author-level permissions or higher to modify arbitrary posts and pages via a REST API end...

Nov 21, 2025
CVE-2025-11773
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify smart contract addresses displayed by the Tok...

Nov 21, 2025
CVE-2025-12169
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to clear scheduled triggers in the ELEX HelpDesk plugin...

Nov 21, 2025
CVE-2025-12022
4.3

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to restor...

Nov 21, 2025
CVE-2025-12023
4.3

The ELEX WordPress HelpDesk plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher to...

Nov 21, 2025
CVE-2025-12085
4.3

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to perman...

Nov 21, 2025
CVE-2025-12751
4.3

The WSChat WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to reset plugin ...

Nov 19, 2025
CVE-2025-12639
4.3

The wModes WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to access...

Nov 18, 2025
CVE-2025-12481
4.3

The WP Duplicate Page WordPress plugin has a missing authorization vulnerability that allows authenticated users with Contributor-level access or high...

Nov 18, 2025
CVE-2025-12961
4.3

The Download Panel WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify pl...

Nov 18, 2025
CVE-2025-12372
4.3

The Permalinks Cascade WordPress plugin has a missing authorization vulnerability that allows authenticated users with subscriber-level access or high...

Nov 18, 2025
CVE-2025-12377
4.3

The Envira Photo Gallery WordPress plugin has an authorization vulnerability that allows authenticated users with Author-level permissions or higher t...

Nov 13, 2025
CVE-2025-64382
4.3

This CVE describes a Missing Authorization vulnerability in the WebToffee Order Export & Order Import for WooCommerce plugin that allows attackers to ...

Nov 13, 2025
CVE-2025-64379
4.3

This CVE describes a missing authorization vulnerability in the Pluggabl Booster for WooCommerce plugin that allows attackers to exploit incorrectly c...

Nov 13, 2025
CVE-2025-64269
4.3

This CVE describes a missing authorization vulnerability in the WooCommerce PDF Invoice Builder WordPress plugin that allows unauthorized users to acc...

Nov 13, 2025
CVE-2025-64274
4.3

This CVE describes a Missing Authorization vulnerability in the WPKoi Templates for Elementor WordPress plugin that allows attackers to exploit incorr...

Nov 13, 2025
CVE-2025-64265
4.3

This CVE describes a Missing Authorization vulnerability in the N-Media Frontend File Manager WordPress plugin (nmedia-user-file-uploader). It allows ...

Nov 13, 2025
CVE-2025-12015
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to disconnect the Afosto service from the Quicq plugin ...

Nov 13, 2025
CVE-2025-12113
4.3

This vulnerability in the Alt Text Generator AI WordPress plugin allows authenticated attackers with Subscriber-level access or higher to delete the A...

Nov 12, 2025
CVE-2025-12953
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to add, update, or delete listing types in the Classifi...

Nov 11, 2025
CVE-2025-42899
4.3

CVE-2025-42899 is an authorization bypass vulnerability in SAP S4CORE's Manage Journal Entries function that allows authenticated users to perform una...

Nov 11, 2025
CVE-2025-42882
4.3

This vulnerability allows authenticated attackers with basic privileges in SAP NetWeaver Application Server for ABAP to execute a specific function mo...

Nov 11, 2025
CVE-2025-48878
4.3

This vulnerability allows authenticated users with Service Desk Agent permissions in Combodo iTop to create ModuleInstallation objects without proper ...

Nov 10, 2025
CVE-2025-12924
4.3

This CVE describes a missing authorization vulnerability in the rymcu forest software's BankController component. Attackers can remotely exploit this ...

Nov 10, 2025
CVE-2025-11448
4.3

The Envira Photo Gallery WordPress plugin has a missing capability check on its bulk-convert REST API endpoint, allowing authenticated users with cont...

Nov 8, 2025
CVE-2025-12498
4.3

The EventPrime WordPress plugin allows authenticated users with Subscriber-level access or higher to add notes to any booking in the backend without p...

Nov 8, 2025
CVE-2025-12167
4.3

The Contact Form 7 AWeber Extension plugin for WordPress has an authorization vulnerability that allows authenticated users with Subscriber-level acce...

Nov 8, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,068 CVEs classified as CWE-862, with 230 rated critical and 870 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free