CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,072
Total CVEs
231
Critical
873
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 126
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,072)

CVE-2025-60148
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Subscribe to Download plugin that allows attackers to bypass intended access...

Sep 26, 2025
CVE-2025-60143
4.3

This CVE describes a missing authorization vulnerability in the Netgsm WordPress plugin that allows attackers to bypass access controls. Attackers cou...

Sep 26, 2025
CVE-2025-60128
4.3

This CVE describes a missing authorization vulnerability in the WordPress Delisho plugin that allows attackers to bypass intended access controls. It ...

Sep 26, 2025
CVE-2025-60122
4.3

This CVE describes a missing authorization vulnerability in the HivePress Claim Listings WordPress plugin that allows attackers to exploit incorrectly...

Sep 26, 2025
CVE-2025-60123
4.3

This CVE describes a missing authorization vulnerability in the HivePress Claim Listings WordPress plugin that allows attackers to exploit incorrectly...

Sep 26, 2025
CVE-2025-60094
4.3

This CVE describes a missing authorization vulnerability in the Stackable WordPress plugin that allows attackers to exploit incorrectly configured acc...

Sep 26, 2025
CVE-2025-59591
4.3

This CVE describes a missing authorization vulnerability in the wpDiscuz WordPress plugin that allows attackers to bypass intended access controls. At...

Sep 22, 2025
CVE-2025-59559
4.3

This CVE describes a Missing Authorization vulnerability in the Payrexx Payment Gateway for WooCommerce plugin that allows attackers to bypass intende...

Sep 22, 2025
CVE-2025-59561
4.3

This CVE describes a missing authorization vulnerability in the hashthemes Smart Blocks WordPress plugin that allows attackers to exploit incorrectly ...

Sep 22, 2025
CVE-2025-59551
4.3

This CVE describes a Missing Authorization vulnerability in the WP Chill Revive.so WordPress plugin that allows attackers to exploit incorrectly confi...

Sep 22, 2025
CVE-2025-58664
4.3

This CVE describes a missing authorization vulnerability in the Azizul Hasan Text To Speech TTS Accessibility WordPress plugin. It allows attackers to...

Sep 22, 2025
CVE-2025-58666
4.3

This CVE describes a missing authorization vulnerability in the Kommo Website Chat Button WordPress plugin that allows attackers to bypass intended ac...

Sep 22, 2025
CVE-2025-58668
4.3

This CVE describes a missing authorization vulnerability in the WPLMS WordPress theme that allows attackers to bypass access controls. It affects all ...

Sep 22, 2025
CVE-2025-58258
4.3

This CVE describes a Missing Authorization vulnerability in the nK Lazy Blocks WordPress plugin that allows attackers to exploit incorrectly configure...

Sep 22, 2025
CVE-2025-58221
4.3

This CVE describes a missing authorization vulnerability in the ONTRAPORT PilotPress WordPress plugin that allows attackers to bypass intended access ...

Sep 22, 2025
CVE-2025-58016
4.3

This CVE describes a missing authorization vulnerability in Codexpert, Inc's CF7 Submissions WordPress plugin that allows attackers to bypass access c...

Sep 22, 2025
CVE-2025-57995
4.3

This CVE describes a Missing Authorization vulnerability in the DethemeKit For Elementor WordPress plugin that allows attackers to exploit incorrectly...

Sep 22, 2025
CVE-2025-57997
4.3

This CVE describes a missing authorization vulnerability in the Trustpilot Reviews WordPress plugin that allows attackers to bypass access controls. I...

Sep 22, 2025
CVE-2025-57985
4.3

This CVE describes a Missing Authorization vulnerability in MantraBrain Ultimate Watermark WordPress plugin that allows attackers to bypass intended a...

Sep 22, 2025
CVE-2025-57975
4.3

This CVE describes a missing authorization vulnerability in the RadiusTheme Team WordPress plugin that allows attackers to bypass intended access cont...

Sep 22, 2025
CVE-2025-57972
4.3

This CVE describes a missing authorization vulnerability in the WPFactory Helpdesk Support Ticket System for WooCommerce plugin. It allows attackers t...

Sep 22, 2025
CVE-2025-57961
4.3

This CVE describes a Missing Authorization vulnerability in Codexpert's CoDesigner WordPress plugin that allows attackers to bypass access controls. I...

Sep 22, 2025
CVE-2025-57936
4.3

This CVE describes a Missing Authorization vulnerability in the Meitar Subresource Integrity (SRI) Manager WordPress plugin that allows attackers to e...

Sep 22, 2025
CVE-2025-57917
4.3

This CVE describes a Missing Authorization vulnerability in the Printcart Web to Print Product Designer for WooCommerce WordPress plugin. It allows at...

Sep 22, 2025
CVE-2025-53452
4.3

This CVE describes a Missing Authorization vulnerability in the Event Rocket WordPress plugin that allows attackers to bypass intended access controls...

Sep 22, 2025
CVE-2025-10489
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to create forms even when the user interface prohibits...

Sep 20, 2025
CVE-2025-59475
4.3

This vulnerability in Jenkins allows authenticated attackers without Overall/Read permission to obtain limited information about Jenkins configuration...

Sep 17, 2025
CVE-2025-8446
4.3

The Blaze Demo Importer WordPress plugin allows authenticated attackers with Subscriber-level access or higher to install and activate specific plugin...

Sep 16, 2025
CVE-2025-43788
4.3

This vulnerability allows authenticated users in Liferay Portal/DXP to enumerate all organizations without proper permission checks. It affects Lifera...

Sep 12, 2025
CVE-2025-0763
4.3

This vulnerability in the Ultimate Classified Listings WordPress plugin allows authenticated attackers with Subscriber-level access or higher to modif...

Sep 11, 2025
CVE-2025-8778
4.3

The NitroPack WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify plu...

Sep 10, 2025
CVE-2025-58976
4.3

This vulnerability allows attackers to bypass authorization controls in the Accessibility Checker WordPress plugin, potentially accessing restricted f...

Sep 9, 2025
CVE-2025-39553
4.3

This CVE describes a Missing Authorization vulnerability in the Church Admin WordPress plugin that allows unauthorized users to access sensitive data....

Sep 9, 2025
CVE-2025-42918
4.3

This vulnerability in SAP NetWeaver Application Server for ABAP allows authenticated users with background processing access to read profile parameter...

Sep 9, 2025
CVE-2025-58824
4.3

This CVE describes a missing authorization vulnerability in the Shk Corporate WordPress theme that allows attackers to bypass access controls. It affe...

Sep 5, 2025
CVE-2025-58813
4.3

This CVE describes a missing authorization vulnerability in the Consultstreet WordPress theme that allows attackers to bypass access controls. Attacke...

Sep 5, 2025
CVE-2025-58817
4.3

This CVE describes a Missing Authorization vulnerability in the SoftMe WordPress theme that allows attackers to bypass access controls. It affects all...

Sep 5, 2025
CVE-2025-58622
4.3

This CVE describes a missing authorization vulnerability in the Mobile Contact Line WordPress plugin that allows attackers to bypass access controls. ...

Sep 3, 2025
CVE-2025-58617
4.3

This CVE describes a missing authorization vulnerability in the FAKTOR VIER F4 Media Taxonomies WordPress plugin that allows attackers to exploit inco...

Sep 3, 2025
CVE-2025-58601
4.3

This CVE describes a Missing Authorization vulnerability in the RadiusTheme Classified Listing WordPress plugin that allows attackers to bypass access...

Sep 3, 2025
CVE-2025-58594
4.3

This CVE describes a Missing Authorization vulnerability in the Brizy WordPress plugin that allows attackers to bypass access controls. It affects all...

Sep 3, 2025
CVE-2025-58599
4.3

This CVE describes a missing authorization vulnerability in the Order Delivery Date for WooCommerce WordPress plugin. It allows attackers to exploit i...

Sep 3, 2025
CVE-2025-3701
4.3

This CVE describes a missing authorization vulnerability in Malcure Malware Scanner WordPress plugin that allows attackers to bypass access controls. ...

Sep 3, 2025
CVE-2025-9219
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to enable premium extensions in the Post SMTP plugin wi...

Sep 3, 2025
CVE-2025-48350
4.3

This CVE describes a missing authorization vulnerability in the AutoWP WordPress plugin that allows attackers to exploit incorrectly configured access...

Aug 28, 2025
CVE-2025-58193
4.3

This CVE describes a missing authorization vulnerability in the Uncanny Automator WordPress plugin that allows attackers to exploit incorrectly config...

Aug 27, 2025
CVE-2025-7827
4.3

The Ni WooCommerce Customer Product Report plugin for WordPress has an authorization vulnerability that allows authenticated users with Subscriber-lev...

Aug 23, 2025
CVE-2025-7828
4.3

The WP Filter & Combine RSS Feeds WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level permissio...

Aug 23, 2025
CVE-2025-9331
4.3

The Spacious WordPress theme has a missing capability check that allows authenticated users with Subscriber-level access or higher to import demo data...

Aug 22, 2025
CVE-2025-57894
4.3

This CVE describes a Missing Authorization vulnerability in the WPPizza WordPress plugin that allows attackers to exploit incorrectly configured acces...

Aug 22, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,072 CVEs classified as CWE-862, with 231 rated critical and 873 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free