CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,072
Total CVEs
231
Critical
873
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 126
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,072)

CVE-2025-48138
4.3

This CVE describes a missing authorization vulnerability in the BERTHA AI WordPress plugin that allows attackers to bypass access controls. It affects...

May 16, 2025
CVE-2025-48128
4.3

This CVE describes a Missing Authorization vulnerability in the Sharespine WooCommerce Connector WordPress plugin that allows attackers to exploit inc...

May 16, 2025
CVE-2025-48079
4.3

This CVE describes a missing authorization vulnerability in ProfileGrid WordPress plugin that allows attackers to bypass access controls and potential...

May 16, 2025
CVE-2025-39511
4.3

This CVE describes a missing authorization vulnerability in the WordPress Pinterest Automatic Pin plugin that allows attackers to bypass access contro...

May 16, 2025
CVE-2025-47534
4.3

This CVE describes a missing authorization vulnerability in the WordPress Auto Spinner plugin that allows attackers to bypass access controls and perf...

May 16, 2025
CVE-2025-39482
4.3

CVE-2025-39482 is a missing authorization vulnerability in the Eventer WordPress plugin that allows attackers to bypass intended access controls. This...

May 16, 2025
CVE-2025-39493
4.3

This CVE describes a missing authorization vulnerability in ValvePress Rankie WordPress plugin that allows attackers to bypass access controls. It aff...

May 16, 2025
CVE-2025-32180
4.3

A missing authorization vulnerability in the CSS3 Tooltips for WordPress plugin allows attackers to bypass access controls and perform unauthorized ac...

May 16, 2025
CVE-2025-31063
4.3

This CVE describes a Missing Authorization vulnerability in the redqteam Wishlist WordPress plugin that allows attackers to exploit incorrectly config...

May 16, 2025
CVE-2025-47692
4.3

This CVE describes a missing authorization vulnerability in the ContentStudio WordPress plugin that allows attackers to bypass access controls. It aff...

May 7, 2025
CVE-2025-47528
4.3

This CVE describes a Missing Authorization vulnerability in the pewilliams Ovation Elements WordPress plugin that allows attackers to bypass intended ...

May 7, 2025
CVE-2025-39413
4.3

This CVE describes a Missing Authorization vulnerability in the Simple Sitemap WordPress plugin that allows unauthorized users to access functionality...

Apr 30, 2025
CVE-2025-3915
4.3

The Aeropage Sync for Airtable WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions o...

Apr 26, 2025
CVE-2025-46470
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Smart Hashtags plugin that allows attackers to exploit incorrectly configure...

Apr 24, 2025
CVE-2025-39385
4.3

This CVE describes a Missing Authorization vulnerability in the Sirat WordPress theme that allows attackers to bypass intended access controls. It aff...

Apr 24, 2025
CVE-2024-12244
4.3

This CVE describes an access control vulnerability in GitLab Enterprise Edition where users can view restricted project information even when related ...

Apr 24, 2025
CVE-2025-46232
4.3

This CVE describes a missing authorization vulnerability in the Download Alt Text AI WordPress plugin that allows unauthorized users to access functio...

Apr 22, 2025
CVE-2025-39571
4.3

This CVE describes a Missing Authorization vulnerability in the WPXPO WowStore WordPress plugin that allows attackers to exploit incorrectly configure...

Apr 16, 2025
CVE-2025-26901
4.3

This CVE describes a missing authorization vulnerability in Brizy Pro WordPress plugin that allows attackers to bypass access controls. It affects all...

Apr 9, 2025
CVE-2025-31004
4.3

This CVE describes a missing authorization vulnerability in the Croover.inc Rich Table of Contents WordPress plugin that allows attackers to exploit i...

Apr 9, 2025
CVE-2025-27437
4.3

This vulnerability allows authenticated non-administrative users in SAP NetWeaver Application Server ABAP to access non-sensitive data through the Vir...

Apr 8, 2025
CVE-2025-1233
4.3

The Lafka WordPress theme plugin allows authenticated users with subscriber-level access or higher to modify theme options that control the entire sit...

Apr 5, 2025
CVE-2025-32277
4.3

This CVE describes a Missing Authorization vulnerability in the RepairBuddy WordPress plugin that allows attackers to bypass access controls. It affec...

Apr 4, 2025
CVE-2025-32237
4.3

A missing authorization vulnerability in Stylemix MasterStudy LMS WordPress plugin allows attackers to bypass intended access controls. This affects a...

Apr 4, 2025
CVE-2025-32239
4.3

This CVE describes a missing authorization vulnerability in the GetSocial.io WordPress plugin that allows attackers to exploit incorrectly configured ...

Apr 4, 2025
CVE-2025-32229
4.3

This CVE describes a Missing Authorization vulnerability in the Bowo Variable Inspector WordPress plugin that allows unauthorized users to exploit inc...

Apr 4, 2025
CVE-2025-32232
4.3

This CVE describes a missing authorization vulnerability in the ERA404 StaffList WordPress plugin that allows attackers to bypass intended access cont...

Apr 4, 2025
CVE-2025-32234
4.3

This CVE describes a Missing Authorization vulnerability in the AdMail WordPress plugin that allows attackers to exploit incorrectly configured access...

Apr 4, 2025
CVE-2025-32201
4.3

This CVE describes a missing authorization vulnerability in the Xpro Theme Builder WordPress plugin that allows attackers to bypass access controls. I...

Apr 4, 2025
CVE-2025-31721
4.3

This vulnerability allows attackers with Computer/Create permission in Jenkins to copy agent configurations and access encrypted secrets they shouldn'...

Apr 2, 2025
CVE-2025-31525
4.3

This CVE describes a missing authorization vulnerability in the WP Mobile Bottom Menu WordPress plugin that allows attackers to bypass intended access...

Apr 1, 2025
CVE-2025-31886
4.3

This CVE describes a missing authorization vulnerability in the Repuso Social Proof Testimonials and Reviews WordPress plugin that allows attackers to...

Apr 1, 2025
CVE-2025-31882
4.3

This CVE describes a Missing Authorization vulnerability in the WPWebinarSystem WebinarPress WordPress plugin, allowing attackers to exploit incorrect...

Apr 1, 2025
CVE-2025-31865
4.3

This CVE describes a Missing Authorization vulnerability in the CartBoss SMS Abandoned Cart Recovery WordPress plugin that allows attackers to exploit...

Apr 1, 2025
CVE-2025-31856
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Export All Post Meta plugin that allows unauthorized users to access functio...

Apr 1, 2025
CVE-2025-31854
4.3

This CVE describes a missing authorization vulnerability in the Simple Sticky Add To Cart For WooCommerce WordPress plugin. It allows attackers to exp...

Apr 1, 2025
CVE-2025-31846
4.3

This CVE describes a missing authorization vulnerability in the Theater for WordPress plugin that allows attackers to bypass intended access controls....

Apr 1, 2025
CVE-2025-31831
4.3

This CVE describes a Missing Authorization vulnerability in the AtomChat WordPress plugin that allows attackers to bypass access controls. Attackers c...

Apr 1, 2025
CVE-2025-31799
4.3

CVE-2025-31799 is a missing authorization vulnerability in the Publitio WordPress plugin that allows attackers to bypass access controls and perform u...

Apr 1, 2025
CVE-2025-31732
4.3

This CVE describes a missing authorization vulnerability in the GB Gallery Slideshow WordPress plugin that allows attackers to bypass access controls....

Apr 1, 2025
CVE-2025-31529
4.3

A missing authorization vulnerability in the Slider Path for Elementor WordPress plugin allows attackers to bypass intended access controls. This affe...

Mar 31, 2025
CVE-2025-31417
4.3

This CVE describes a Missing Authorization vulnerability in the WP Docs WordPress plugin that allows attackers to bypass intended access controls. It ...

Mar 31, 2025
CVE-2025-22671
4.3

This CVE describes a missing authorization vulnerability in the WordPress 'Disable Elementor Editor Translation' plugin that allows attackers to bypas...

Mar 27, 2025
CVE-2025-30909
4.3

This CVE describes a missing authorization vulnerability in the Conversios.io WordPress plugin that allows attackers to bypass access controls. It aff...

Mar 27, 2025
CVE-2025-30881
4.3

This CVE describes a missing authorization vulnerability in the ThemeHunk Big Store WordPress theme that allows attackers to bypass access controls. I...

Mar 27, 2025
CVE-2025-30874
4.3

This CVE describes a missing authorization vulnerability in the WordPress plugin 'Specific Content For Mobile' that allows attackers to bypass access ...

Mar 27, 2025
CVE-2025-30851
4.3

This CVE describes a missing authorization vulnerability in the Tickera WordPress plugin that allows attackers to bypass access controls. It affects a...

Mar 27, 2025
CVE-2025-24972
4.3

Discourse users who disabled direct messaging in their preferences could still be added to group direct messages in specific circumstances. This affec...

Mar 26, 2025
CVE-2025-30605
4.3

This CVE describes a missing authorization vulnerability in the sourceplay-navermap WordPress plugin that allows attackers to bypass access controls. ...

Mar 24, 2025
CVE-2025-1408
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to approve or decline group join requests, which should...

Mar 22, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,072 CVEs classified as CWE-862, with 231 rated critical and 873 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free