CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,072)
This CVE describes a missing authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to bypass access controls. It affects...
May 16, 2025This CVE describes a Missing Authorization vulnerability in the Sharespine WooCommerce Connector WordPress plugin that allows attackers to exploit inc...
May 16, 2025This CVE describes a missing authorization vulnerability in ProfileGrid WordPress plugin that allows attackers to bypass access controls and potential...
May 16, 2025This CVE describes a missing authorization vulnerability in the WordPress Pinterest Automatic Pin plugin that allows attackers to bypass access contro...
May 16, 2025This CVE describes a missing authorization vulnerability in the WordPress Auto Spinner plugin that allows attackers to bypass access controls and perf...
May 16, 2025CVE-2025-39482 is a missing authorization vulnerability in the Eventer WordPress plugin that allows attackers to bypass intended access controls. This...
May 16, 2025This CVE describes a missing authorization vulnerability in ValvePress Rankie WordPress plugin that allows attackers to bypass access controls. It aff...
May 16, 2025A missing authorization vulnerability in the CSS3 Tooltips for WordPress plugin allows attackers to bypass access controls and perform unauthorized ac...
May 16, 2025This CVE describes a Missing Authorization vulnerability in the redqteam Wishlist WordPress plugin that allows attackers to exploit incorrectly config...
May 16, 2025This CVE describes a missing authorization vulnerability in the ContentStudio WordPress plugin that allows attackers to bypass access controls. It aff...
May 7, 2025This CVE describes a Missing Authorization vulnerability in the pewilliams Ovation Elements WordPress plugin that allows attackers to bypass intended ...
May 7, 2025This CVE describes a Missing Authorization vulnerability in the Simple Sitemap WordPress plugin that allows unauthorized users to access functionality...
Apr 30, 2025The Aeropage Sync for Airtable WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions o...
Apr 26, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Smart Hashtags plugin that allows attackers to exploit incorrectly configure...
Apr 24, 2025This CVE describes a Missing Authorization vulnerability in the Sirat WordPress theme that allows attackers to bypass intended access controls. It aff...
Apr 24, 2025This CVE describes an access control vulnerability in GitLab Enterprise Edition where users can view restricted project information even when related ...
Apr 24, 2025This CVE describes a missing authorization vulnerability in the Download Alt Text AI WordPress plugin that allows unauthorized users to access functio...
Apr 22, 2025This CVE describes a Missing Authorization vulnerability in the WPXPO WowStore WordPress plugin that allows attackers to exploit incorrectly configure...
Apr 16, 2025This CVE describes a missing authorization vulnerability in Brizy Pro WordPress plugin that allows attackers to bypass access controls. It affects all...
Apr 9, 2025This CVE describes a missing authorization vulnerability in the Croover.inc Rich Table of Contents WordPress plugin that allows attackers to exploit i...
Apr 9, 2025This vulnerability allows authenticated non-administrative users in SAP NetWeaver Application Server ABAP to access non-sensitive data through the Vir...
Apr 8, 2025The Lafka WordPress theme plugin allows authenticated users with subscriber-level access or higher to modify theme options that control the entire sit...
Apr 5, 2025This CVE describes a Missing Authorization vulnerability in the RepairBuddy WordPress plugin that allows attackers to bypass access controls. It affec...
Apr 4, 2025A missing authorization vulnerability in Stylemix MasterStudy LMS WordPress plugin allows attackers to bypass intended access controls. This affects a...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the GetSocial.io WordPress plugin that allows attackers to exploit incorrectly configured ...
Apr 4, 2025This CVE describes a Missing Authorization vulnerability in the Bowo Variable Inspector WordPress plugin that allows unauthorized users to exploit inc...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the ERA404 StaffList WordPress plugin that allows attackers to bypass intended access cont...
Apr 4, 2025This CVE describes a Missing Authorization vulnerability in the AdMail WordPress plugin that allows attackers to exploit incorrectly configured access...
Apr 4, 2025This CVE describes a missing authorization vulnerability in the Xpro Theme Builder WordPress plugin that allows attackers to bypass access controls. I...
Apr 4, 2025This vulnerability allows attackers with Computer/Create permission in Jenkins to copy agent configurations and access encrypted secrets they shouldn'...
Apr 2, 2025This CVE describes a missing authorization vulnerability in the WP Mobile Bottom Menu WordPress plugin that allows attackers to bypass intended access...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the Repuso Social Proof Testimonials and Reviews WordPress plugin that allows attackers to...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the WPWebinarSystem WebinarPress WordPress plugin, allowing attackers to exploit incorrect...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the CartBoss SMS Abandoned Cart Recovery WordPress plugin that allows attackers to exploit...
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Export All Post Meta plugin that allows unauthorized users to access functio...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the Simple Sticky Add To Cart For WooCommerce WordPress plugin. It allows attackers to exp...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass intended access controls....
Apr 1, 2025This CVE describes a Missing Authorization vulnerability in the AtomChat WordPress plugin that allows attackers to bypass access controls. Attackers c...
Apr 1, 2025CVE-2025-31799 is a missing authorization vulnerability in the Publitio WordPress plugin that allows attackers to bypass access controls and perform u...
Apr 1, 2025This CVE describes a missing authorization vulnerability in the GB Gallery Slideshow WordPress plugin that allows attackers to bypass access controls....
Apr 1, 2025A missing authorization vulnerability in the Slider Path for Elementor WordPress plugin allows attackers to bypass intended access controls. This affe...
Mar 31, 2025This CVE describes a Missing Authorization vulnerability in the WP Docs WordPress plugin that allows attackers to bypass intended access controls. It ...
Mar 31, 2025This CVE describes a missing authorization vulnerability in the WordPress 'Disable Elementor Editor Translation' plugin that allows attackers to bypas...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the Conversios.io WordPress plugin that allows attackers to bypass access controls. It aff...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the ThemeHunk Big Store WordPress theme that allows attackers to bypass access controls. I...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the WordPress plugin 'Specific Content For Mobile' that allows attackers to bypass access ...
Mar 27, 2025This CVE describes a missing authorization vulnerability in the Tickera WordPress plugin that allows attackers to bypass access controls. It affects a...
Mar 27, 2025Discourse users who disabled direct messaging in their preferences could still be added to group direct messages in specific circumstances. This affec...
Mar 26, 2025This CVE describes a missing authorization vulnerability in the sourceplay-navermap WordPress plugin that allows attackers to bypass access controls. ...
Mar 24, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to approve or decline group join requests, which should...
Mar 22, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,072 CVEs classified as CWE-862, with 231 rated critical and 873 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free