CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,069
Total CVEs
230
Critical
871
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,069)

CVE-2025-12167
4.3

The Contact Form 7 AWeber Extension plugin for WordPress has an authorization vulnerability that allows authenticated users with Subscriber-level acce...

Nov 8, 2025
CVE-2025-12527
4.3

The Page & Post Notes WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or hi...

Nov 7, 2025
CVE-2025-12469
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to send arbitrary emails from the site with attacker-co...

Nov 5, 2025
CVE-2025-12675
4.3

The KiotViet Sync WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify...

Nov 5, 2025
CVE-2025-11373
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to upload arbitrary files to affected servers due to m...

Nov 5, 2025
CVE-2025-12582
4.3

The Features plugin for WordPress has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to revert ...

Nov 5, 2025
CVE-2025-12389
4.3

The Import Export For WooCommerce WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level acc...

Nov 4, 2025
CVE-2025-12156
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create and publish arbitrary posts without proper au...

Nov 4, 2025
CVE-2025-64358
4.3

This CVE describes a missing authorization vulnerability in the WebToffee Smart Coupons for WooCommerce plugin that allows attackers to bypass access ...

Oct 31, 2025
CVE-2025-64356
4.3

This CVE describes a missing authorization vulnerability in the Insert PHP Code Snippet WordPress plugin that allows attackers to exploit incorrectly ...

Oct 31, 2025
CVE-2025-12175
4.3

The Events Calendar WordPress plugin versions up to 6.15.9 have an authorization vulnerability where authenticated users with Subscriber-level permiss...

Oct 31, 2025
CVE-2025-11975
4.3

The FuseWP WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to modify sync rules between WordPress use...

Oct 31, 2025
CVE-2025-64148
4.3

The Jenkins Publish to Bitbucket Plugin before version 0.5 has a missing permission check that allows authenticated attackers with only Overall/Read p...

Oct 29, 2025
CVE-2025-64137
4.3

The Jenkins Themis Plugin 1.4.1 and earlier contains a missing permission check vulnerability that allows authenticated attackers with Overall/Read pe...

Oct 29, 2025
CVE-2025-64139
4.3

This vulnerability in Jenkins Start Windocks Containers Plugin allows attackers with Overall/Read permission to connect to arbitrary URLs, potentially...

Oct 29, 2025
CVE-2025-64142
4.3

The Jenkins Nexus Task Runner Plugin before version 0.9.3 has a missing permission check vulnerability. Attackers with Overall/Read permission can for...

Oct 29, 2025
CVE-2025-11632
4.3

This vulnerability in the Call Now Button WordPress plugin allows authenticated attackers with Subscriber-level access or higher to access and modify ...

Oct 29, 2025
CVE-2025-11587
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to link the vulnerable plugin to external nowbuttons.co...

Oct 29, 2025
CVE-2025-64229
4.3

This CVE describes a missing authorization vulnerability in the BoldGrid Client Invoicing by Sprout Invoices WordPress plugin. It allows attackers to ...

Oct 29, 2025
CVE-2025-64234
4.3

This CVE describes a missing authorization vulnerability in the Evergreen Content Poster WordPress plugin that allows attackers to exploit incorrectly...

Oct 29, 2025
CVE-2025-62978
4.3

This CVE describes a Missing Authorization vulnerability in the KiotViet Sync WordPress plugin that allows attackers to bypass access controls. It aff...

Oct 27, 2025
CVE-2025-62972
4.3

This CVE describes a missing authorization vulnerability in the WebinarPress WordPress plugin (formerly WPWebinarSystem) that allows attackers to bypa...

Oct 27, 2025
CVE-2025-62883
4.3

This CVE describes a Missing Authorization vulnerability in the Premmerce User Roles WordPress plugin that allows attackers to exploit incorrectly con...

Oct 27, 2025
CVE-2025-62881
4.3

This CVE describes a missing authorization vulnerability in WP-Lister Lite for eBay WordPress plugin that allows attackers to bypass access controls. ...

Oct 27, 2025
CVE-2025-62882
4.3

This CVE describes a missing authorization vulnerability in the Seriously Simple Podcasting WordPress plugin that allows attackers to exploit incorrec...

Oct 27, 2025
CVE-2025-11255
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to disconnect the site's connection to miniorange servi...

Oct 25, 2025
CVE-2025-12014
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify the NGINX Cache Optimizer plugin's blacklist ...

Oct 24, 2025
CVE-2025-11172
4.3

The Check Plagiarism WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher t...

Oct 24, 2025
CVE-2025-10901
4.3

The Originality.ai AI Checker WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or high...

Oct 24, 2025
CVE-2025-22178
4.3

Jira Align has an authorization vulnerability where low-privilege users can access endpoints they shouldn't, potentially viewing sensitive information...

Oct 22, 2025
CVE-2025-62072
4.3

This CVE describes a Missing Authorization vulnerability in the Rustaurius Front End Users WordPress plugin that allows unauthorized users to access f...

Oct 22, 2025
CVE-2025-62073
4.3

This CVE describes a Missing Authorization vulnerability in the Sovlix MeetingHub WordPress plugin that allows unauthorized users to access functional...

Oct 22, 2025
CVE-2025-62070
4.3

This CVE describes a Missing Authorization vulnerability in the WPXPO WowRevenue WordPress plugin that allows unauthorized users to access functionali...

Oct 22, 2025
CVE-2025-62071
4.3

This CVE describes a Missing Authorization vulnerability in the Repuso Social Proof Testimonials and Reviews WordPress plugin. It allows attackers to ...

Oct 22, 2025
CVE-2025-62052
4.3

This CVE describes a Missing Authorization vulnerability in the One Page Express Companion WordPress plugin. It allows attackers to perform actions wi...

Oct 22, 2025
CVE-2025-62013
4.3

This CVE describes a missing authorization vulnerability in the POSIMYTH UiChemy WordPress plugin. It allows authenticated users to perform actions th...

Oct 22, 2025
CVE-2025-49937
4.3

This vulnerability allows attackers to bypass authorization controls in the Smash Balloon Social Post Feed WordPress plugin, potentially accessing res...

Oct 22, 2025
CVE-2025-49907
4.3

This CVE describes a missing authorization vulnerability in the RealMag777 MDTF WordPress plugin that allows attackers to bypass intended access contr...

Oct 22, 2025
CVE-2025-11742
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view other users' wishlist data through the WPC Smar...

Oct 18, 2025
CVE-2025-41443
4.3

This vulnerability allows guest users in Mattermost to discover active public channels and their metadata through an API endpoint, bypassing intended ...

Oct 16, 2025
CVE-2025-10303
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify plugin settings and features without proper a...

Oct 15, 2025
CVE-2025-10732
4.3

The SureForms WordPress plugin has an access control vulnerability in its REST API endpoint that allows authenticated users with contributor-level per...

Oct 14, 2025
CVE-2025-8682
4.3

The Newsup WordPress theme has a vulnerability that allows unauthenticated attackers to install the ansar-import plugin without proper authorization. ...

Oct 11, 2025
CVE-2025-11439
4.3

This vulnerability allows unauthorized access to the /show/integrations endpoint in JhumanJ OpnForm up to version 1.9.3. Attackers can exploit this mi...

Oct 8, 2025
CVE-2025-9029
4.3

This vulnerability allows unauthenticated attackers to submit feedback data to external services via the WDesignKit WordPress plugin. It affects WordP...

Oct 4, 2025
CVE-2025-60166
4.3

This CVE describes a Missing Authorization vulnerability in WP Subscription Forms PRO WordPress plugin that allows unauthorized users to delete arbitr...

Sep 26, 2025
CVE-2025-60159
4.3

This CVE describes a Missing Authorization vulnerability in the Nota Fiscal Eletrônica WooCommerce WordPress plugin that allows attackers to exploit ...

Sep 26, 2025
CVE-2025-60148
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Subscribe to Download plugin that allows attackers to bypass intended access...

Sep 26, 2025
CVE-2025-60143
4.3

This CVE describes a missing authorization vulnerability in the Netgsm WordPress plugin that allows attackers to bypass access controls. Attackers cou...

Sep 26, 2025
CVE-2025-60128
4.3

This CVE describes a missing authorization vulnerability in the WordPress Delisho plugin that allows attackers to bypass intended access controls. It ...

Sep 26, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,069 CVEs classified as CWE-862, with 230 rated critical and 871 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free