CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,072)
This CVE describes a missing authorization vulnerability in the Greenshift WordPress plugin that allows attackers to bypass intended access controls. ...
Aug 22, 2025A missing authorization vulnerability in the Themify Builder WordPress plugin allows attackers to bypass intended access controls. This affects all ve...
Aug 20, 2025The ColorMag WordPress theme has a missing capability check that allows authenticated users with Subscriber-level access or higher to install the Them...
Aug 20, 2025The Media Library Assistant WordPress plugin allows authenticated attackers with Author-level permissions or higher to delete arbitrary files from the...
Aug 19, 2025This CVE describes a missing authorization vulnerability in the WP Statistics WordPress plugin that allows attackers to bypass intended access control...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the Easy Elementor Addons WordPress plugin that allows attackers to exploit incorrectly co...
Aug 14, 2025CVE-2025-53341 is a missing authorization vulnerability in the Themovation Stratus WordPress theme that allows attackers to bypass access controls. Th...
Aug 14, 2025CVE-2025-53343 is a missing authorization vulnerability in the GoodLayers Modernize WordPress theme that allows attackers to bypass access controls an...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the CodeablePress WordPress plugin that allows attackers to exploit incorrectly configured...
Aug 14, 2025This vulnerability allows authenticated low-privileged users on Cisco Secure FMC to bypass authorization checks and access reports from different doma...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the WpEvently WordPress plugin that allows attackers to bypass intended access controls. A...
Aug 14, 2025This CVE describes a missing authorization vulnerability in the Dariolee Netease Music WordPress plugin that allows attackers to bypass access control...
Aug 14, 2025The Simple Local Avatars WordPress plugin version 2.8.4 has an authorization vulnerability that allows authenticated users (even subscribers) to modif...
Aug 12, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify compatibility option settings in the Ultimate...
Aug 2, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify opt-in status settings without proper authori...
Jul 29, 2025The WP Wallcreeper WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level permissions or hig...
Jul 24, 2025This vulnerability allows unauthorized users to read deployment job logs in GitLab by sending specially crafted requests. It affects GitLab Community ...
Jul 24, 2025The Block Editor Gallery Slider WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or hi...
Jul 18, 2025This CVE describes a Missing Authorization vulnerability in the Bill Minozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WordPress...
Jul 16, 2025This CVE describes a missing authorization vulnerability in the LMSACE Connect WordPress plugin that allows attackers to bypass intended access contro...
Jul 4, 2025This CVE describes an authorization vulnerability in n8n workflow automation platform where authenticated users can stop workflow executions they don'...
Jul 3, 2025This CVE describes a missing authorization vulnerability in the Dashboard Widget Sidebar WordPress plugin that allows attackers to bypass access contr...
Jun 27, 2025CVE-2025-53266 is a missing authorization vulnerability in the EdwardBock Cron Logger WordPress plugin that allows unauthorized users to access functi...
Jun 27, 2025This CVE describes a missing authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....
Jun 27, 2025This vulnerability allows authenticated users with Guest role permissions in GitLab to bypass UI-enforced restrictions and add child items to incident...
Jun 26, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to abuse the Post Carousel Slider for Elementor plugin'...
Jun 26, 2025This vulnerability in JetBrains TeamCity exposes usernames to users who lack proper permissions to view them. It affects organizations using TeamCity ...
Jun 23, 2025This CVE describes a missing authorization vulnerability in the WP Customer Area WordPress plugin that allows attackers to bypass access controls and ...
Jun 20, 2025CVE-2025-49976 is a missing authorization vulnerability in the WANotifier WordPress plugin that allows attackers to bypass intended access controls. T...
Jun 20, 2025This CVE describes a missing authorization vulnerability in the WP User Profile Avatar WordPress plugin that allows attackers to bypass access control...
Jun 20, 2025This CVE describes a Missing Authorization vulnerability in the Hello FSE Blog WordPress theme that allows attackers to bypass intended access control...
Jun 20, 2025This CVE describes a missing authorization vulnerability in the UpStream WordPress plugin that allows attackers to bypass access controls and perform ...
Jun 20, 2025A missing authorization vulnerability in the Cloudways Breeze WordPress plugin allows attackers to bypass intended access controls. This affects all B...
Jun 18, 2025SAP S/4HANA Bank Account Application has an authorization vulnerability where authenticated 'approver' users can delete attachments from other users' ...
Jun 10, 2025This vulnerability allows authenticated attackers with basic privileges to edit shared processing rules for bank statements that should be restricted ...
Jun 10, 2025This CVE describes a Missing Authorization vulnerability in the WordPress plugin Crawlomatic Multisite Scraper Post Generator that allows attackers to...
Jun 6, 2025This vulnerability allows attackers to bypass authorization controls in the Ultimate WP Mail WordPress plugin, potentially accessing administrative fu...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the Testimonials Showcase WordPress plugin that allows attackers to exploit incorrectly co...
Jun 6, 2025This CVE describes a missing authorization vulnerability in the Post Grid Master WordPress plugin that allows attackers to bypass access controls. Att...
Jun 6, 2025CVE-2025-29010 is a missing authorization vulnerability in the Behance Portfolio Manager WordPress plugin that allows attackers to bypass access contr...
Jun 6, 2025This CVE describes a Missing Authorization vulnerability in the GPP Slideshow WordPress plugin that allows attackers to bypass access controls. It aff...
Jun 6, 2025This CVE describes a missing authorization vulnerability in the Viral Loops WP Integration WordPress plugin that allows attackers to bypass intended a...
Jun 6, 2025This CVE describes a missing authorization vulnerability in the 6Storage Rentals WordPress plugin that allows attackers to bypass access controls. It ...
Jun 6, 2025The Art Theme for WordPress has a missing capability check in its 'arttheme_theme_option_restore' AJAX function, allowing authenticated users with sub...
Jun 6, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Mautic's segment cloning functionality. Any authenticated user can clon...
May 28, 2025The MStore API WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher to crea...
May 27, 2025A missing authorization vulnerability in the Master Slider WordPress plugin allows attackers to perform actions without proper authentication. This af...
May 19, 2025This CVE describes a missing authorization vulnerability in the Car Park Booking System for WordPress plugin. It allows unauthorized users to access f...
May 19, 2025This CVE describes a Missing Authorization vulnerability in the Guru Team Bot for Telegram on WooCommerce WordPress plugin. It allows attackers to byp...
May 19, 2025This CVE describes a missing authorization vulnerability in the Ninja Team GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypa...
May 19, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,072 CVEs classified as CWE-862, with 231 rated critical and 873 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free