CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,072
Total CVEs
231
Critical
873
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 126
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,072)

CVE-2025-57884
4.3

This CVE describes a missing authorization vulnerability in the Greenshift WordPress plugin that allows attackers to bypass intended access controls. ...

Aug 22, 2025
CVE-2025-49396
4.3

A missing authorization vulnerability in the Themify Builder WordPress plugin allows attackers to bypass intended access controls. This affects all ve...

Aug 20, 2025
CVE-2025-9202
4.3

The ColorMag WordPress theme has a missing capability check that allows authenticated users with Subscriber-level access or higher to install the Them...

Aug 20, 2025
CVE-2025-8357
4.3

The Media Library Assistant WordPress plugin allows authenticated attackers with Author-level permissions or higher to delete arbitrary files from the...

Aug 19, 2025
CVE-2025-55716
4.3

This CVE describes a missing authorization vulnerability in the WP Statistics WordPress plugin that allows attackers to bypass intended access control...

Aug 14, 2025
CVE-2025-54712
4.3

This CVE describes a missing authorization vulnerability in the Easy Elementor Addons WordPress plugin that allows attackers to exploit incorrectly co...

Aug 14, 2025
CVE-2025-53341
4.3

CVE-2025-53341 is a missing authorization vulnerability in the Themovation Stratus WordPress theme that allows attackers to bypass access controls. Th...

Aug 14, 2025
CVE-2025-53343
4.3

CVE-2025-53343 is a missing authorization vulnerability in the GoodLayers Modernize WordPress theme that allows attackers to bypass access controls an...

Aug 14, 2025
CVE-2025-53221
4.3

This CVE describes a missing authorization vulnerability in the CodeablePress WordPress plugin that allows attackers to exploit incorrectly configured...

Aug 14, 2025
CVE-2025-20302
4.3

This vulnerability allows authenticated low-privileged users on Cisco Secure FMC to bypass authorization checks and access reports from different doma...

Aug 14, 2025
CVE-2025-54705
4.3

This CVE describes a missing authorization vulnerability in the WpEvently WordPress plugin that allows attackers to bypass intended access controls. A...

Aug 14, 2025
CVE-2025-49052
4.3

This CVE describes a missing authorization vulnerability in the Dariolee Netease Music WordPress plugin that allows attackers to bypass access control...

Aug 14, 2025
CVE-2025-8482
4.3

The Simple Local Avatars WordPress plugin version 2.8.4 has an authorization vulnerability that allows authenticated users (even subscribers) to modif...

Aug 12, 2025
CVE-2025-8488
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify compatibility option settings in the Ultimate...

Aug 2, 2025
CVE-2025-6730
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify opt-in status settings without proper authori...

Jul 29, 2025
CVE-2025-7822
4.3

The WP Wallcreeper WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level permissions or hig...

Jul 24, 2025
CVE-2025-1299
4.3

This vulnerability allows unauthorized users to read deployment job logs in GitLab by sending specially crafted requests. It affects GitLab Community ...

Jul 24, 2025
CVE-2025-6726
4.3

The Block Editor Gallery Slider WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or hi...

Jul 18, 2025
CVE-2025-48150
4.3

This CVE describes a Missing Authorization vulnerability in the Bill Minozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WordPress...

Jul 16, 2025
CVE-2025-29007
4.3

This CVE describes a missing authorization vulnerability in the LMSACE Connect WordPress plugin that allows attackers to bypass intended access contro...

Jul 4, 2025
CVE-2025-52554
4.3

This CVE describes an authorization vulnerability in n8n workflow automation platform where authenticated users can stop workflow executions they don'...

Jul 3, 2025
CVE-2025-53293
4.3

This CVE describes a missing authorization vulnerability in the Dashboard Widget Sidebar WordPress plugin that allows attackers to bypass access contr...

Jun 27, 2025
CVE-2025-53266
4.3

CVE-2025-53266 is a missing authorization vulnerability in the EdwardBock Cron Logger WordPress plugin that allows unauthorized users to access functi...

Jun 27, 2025
CVE-2025-53200
4.3

This CVE describes a missing authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....

Jun 27, 2025
CVE-2025-5315
4.3

This vulnerability allows authenticated users with Guest role permissions in GitLab to bypass UI-enforced restrictions and add child items to incident...

Jun 26, 2025
CVE-2025-3863
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to abuse the Post Carousel Slider for Elementor plugin'...

Jun 26, 2025
CVE-2025-52878
4.3

This vulnerability in JetBrains TeamCity exposes usernames to users who lack proper permissions to view them. It affects organizations using TeamCity ...

Jun 23, 2025
CVE-2025-49982
4.3

This CVE describes a missing authorization vulnerability in the WP Customer Area WordPress plugin that allows attackers to bypass access controls and ...

Jun 20, 2025
CVE-2025-49976
4.3

CVE-2025-49976 is a missing authorization vulnerability in the WANotifier WordPress plugin that allows attackers to bypass intended access controls. T...

Jun 20, 2025
CVE-2025-49980
4.3

This CVE describes a missing authorization vulnerability in the WP User Profile Avatar WordPress plugin that allows attackers to bypass access control...

Jun 20, 2025
CVE-2025-49970
4.3

This CVE describes a Missing Authorization vulnerability in the Hello FSE Blog WordPress theme that allows attackers to bypass intended access control...

Jun 20, 2025
CVE-2025-49974
4.3

This CVE describes a missing authorization vulnerability in the UpStream WordPress plugin that allows attackers to bypass access controls and perform ...

Jun 20, 2025
CVE-2025-23999
4.3

A missing authorization vulnerability in the Cloudways Breeze WordPress plugin allows attackers to bypass intended access controls. This affects all B...

Jun 18, 2025
CVE-2025-42991
4.3

SAP S/4HANA Bank Account Application has an authorization vulnerability where authenticated 'approver' users can delete attachments from other users' ...

Jun 10, 2025
CVE-2025-42987
4.3

This vulnerability allows authenticated attackers with basic privileges to edit shared processing rules for bank statements that should be restricted ...

Jun 10, 2025
CVE-2025-49293
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress plugin Crawlomatic Multisite Scraper Post Generator that allows attackers to...

Jun 6, 2025
CVE-2025-49288
4.3

This vulnerability allows attackers to bypass authorization controls in the Ultimate WP Mail WordPress plugin, potentially accessing administrative fu...

Jun 6, 2025
CVE-2025-49246
4.3

This CVE describes a Missing Authorization vulnerability in the Testimonials Showcase WordPress plugin that allows attackers to exploit incorrectly co...

Jun 6, 2025
CVE-2025-30974
4.3

This CVE describes a missing authorization vulnerability in the Post Grid Master WordPress plugin that allows attackers to bypass access controls. Att...

Jun 6, 2025
CVE-2025-29010
4.3

CVE-2025-29010 is a missing authorization vulnerability in the Behance Portfolio Manager WordPress plugin that allows attackers to bypass access contr...

Jun 6, 2025
CVE-2025-28996
4.3

This CVE describes a Missing Authorization vulnerability in the GPP Slideshow WordPress plugin that allows attackers to bypass access controls. It aff...

Jun 6, 2025
CVE-2025-28994
4.3

This CVE describes a missing authorization vulnerability in the Viral Loops WP Integration WordPress plugin that allows attackers to bypass intended a...

Jun 6, 2025
CVE-2023-26002
4.3

This CVE describes a missing authorization vulnerability in the 6Storage Rentals WordPress plugin that allows attackers to bypass access controls. It ...

Jun 6, 2025
CVE-2025-1778
4.3

The Art Theme for WordPress has a missing capability check in its 'arttheme_theme_option_restore' AJAX function, allowing authenticated users with sub...

Jun 6, 2025
CVE-2024-47055
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Mautic's segment cloning functionality. Any authenticated user can clon...

May 28, 2025
CVE-2025-4683
4.3

The MStore API WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher to crea...

May 27, 2025
CVE-2025-39412
4.3

A missing authorization vulnerability in the Master Slider WordPress plugin allows attackers to perform actions without proper authentication. This af...

May 19, 2025
CVE-2025-39376
4.3

This CVE describes a missing authorization vulnerability in the Car Park Booking System for WordPress plugin. It allows unauthorized users to access f...

May 19, 2025
CVE-2025-48268
4.3

This CVE describes a Missing Authorization vulnerability in the Guru Team Bot for Telegram on WooCommerce WordPress plugin. It allows attackers to byp...

May 19, 2025
CVE-2025-48260
4.3

This CVE describes a missing authorization vulnerability in the Ninja Team GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypa...

May 19, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,072 CVEs classified as CWE-862, with 231 rated critical and 873 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free