CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,074
Total CVEs
231
Critical
874
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
441
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 126
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,074)

CVE-2025-30605
4.3

This CVE describes a missing authorization vulnerability in the sourceplay-navermap WordPress plugin that allows attackers to bypass access controls. ...

Mar 24, 2025
CVE-2025-1408
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to approve or decline group join requests, which should...

Mar 22, 2025
CVE-2024-7045
4.3

This vulnerability in open-webui v0.3.8 allows attackers to bypass access controls and view all prompts created by administrators. Attackers can retri...

Mar 20, 2025
CVE-2025-1668
4.3

The WPSchoolPress WordPress plugin has a missing capability check that allows authenticated users with teacher-level access or higher to delete any us...

Mar 15, 2025
CVE-2025-2289
4.3

The Zegen Church WordPress theme has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or higher ...

Mar 14, 2025
CVE-2025-2104
4.3

This vulnerability in the Pagelayer WordPress plugin allows authenticated users with Contributor-level access or higher to bypass post moderation and ...

Mar 13, 2025
CVE-2024-13703
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to enable/disable plugin widgets without proper authori...

Mar 13, 2025
CVE-2025-28938
4.3

This CVE describes a missing authorization vulnerability in the WP Performance Pack WordPress plugin that allows attackers to exploit incorrectly conf...

Mar 11, 2025
CVE-2025-26656
4.3

This vulnerability in SAP's Manage Purchasing Info Records OData service allows authenticated users to escalate privileges due to missing authorizatio...

Mar 11, 2025
CVE-2025-23188
4.3

An authenticated low-privilege user can exploit a missing authorization check in the IBS module of FS-RBD to perform unauthorized actions beyond their...

Mar 11, 2025
CVE-2025-1504
4.3

The Post Lockdown WordPress plugin has an information exposure vulnerability that allows authenticated users with Subscriber-level access or higher to...

Mar 8, 2025
CVE-2024-13810
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to import demo content and overwrite the site through A...

Mar 5, 2025
CVE-2024-13686
4.3

The VW Storefront WordPress theme has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher ...

Mar 4, 2025
CVE-2025-1780
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify plugin page settings without proper authoriza...

Mar 1, 2025
CVE-2024-13716
4.3

The Forex Calculators WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher ...

Feb 28, 2025
CVE-2025-1091
4.3

This CVE describes a broken authorization vulnerability where authenticated users can download IOA script and configuration files by knowing specific ...

Feb 26, 2025
CVE-2025-26983
4.3

This CVE describes a Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for WordPress that allows unauthorized users to access functiona...

Feb 25, 2025
CVE-2025-26871
4.3

This CVE describes a Missing Authorization vulnerability in WPDeveloper's Essential Blocks for Gutenberg WordPress plugin. It allows attackers to expl...

Feb 25, 2025
CVE-2024-13687
4.3

The Team Builder WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify ...

Feb 18, 2025
CVE-2024-13439
4.3

The Team – Team Members Showcase Plugin for WordPress has a missing capability check in its response() function, allowing authenticated attackers wi...

Feb 15, 2025
CVE-2024-13639
4.3

The Read More & Accordion WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...

Feb 13, 2025
CVE-2025-26367
4.3

This vulnerability allows authenticated low-privileged attackers to create arbitrary user groups in Q-Free MaxTime traffic management systems. Attacke...

Feb 12, 2025
CVE-2024-13374
4.3

The WP Table Manager WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to rea...

Feb 12, 2025
CVE-2025-23190
4.3

This CVE describes an authorization bypass vulnerability in SAP systems where authenticated users can access unauthorized data through a remote-enable...

Feb 11, 2025
CVE-2024-1539
4.3

This vulnerability allows banned group members to access updates to issues via the GitLab API, potentially exposing sensitive information about issue ...

Feb 5, 2025
CVE-2025-22643
4.3

A missing authorization vulnerability in the FameThemes OnePress WordPress theme allows attackers to bypass access controls and potentially modify the...

Feb 4, 2025
CVE-2024-11134
4.3

The Eventer WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level permissions or higher to downloa...

Feb 3, 2025
CVE-2025-22694
4.3

This CVE describes a Missing Authorization vulnerability in the Hide Shipping Method For WooCommerce plugin that allows unauthorized users to access f...

Feb 3, 2025
CVE-2025-22681
4.3

This CVE describes a Missing Authorization vulnerability in the Xfinity Soft Content Cloner WordPress plugin that allows attackers to exploit incorrec...

Feb 3, 2025
CVE-2024-50500
4.3

This CVE describes a Missing Authorization vulnerability in the Shortcodes and extra features for Phlox theme WordPress plugin. It allows attackers to...

Feb 3, 2025
CVE-2024-13530
4.3

This vulnerability in the WordPress Login Page Styler plugin allows authenticated attackers with Subscriber-level access or higher to delete login log...

Jan 31, 2025
CVE-2024-13415
4.3

The Food Menu plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify plu...

Jan 31, 2025
CVE-2024-13717
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to enable or disable widgets without proper authorizati...

Jan 31, 2025
CVE-2024-13715
4.3

The zStore Manager Basic WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or...

Jan 30, 2025
CVE-2024-13652
4.3

The ECPay Ecommerce for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access o...

Jan 30, 2025
CVE-2025-24744
4.3

CVE-2025-24744 is a missing authorization vulnerability in the Bridge Core WordPress plugin that allows attackers to bypass access controls. This affe...

Jan 27, 2025
CVE-2025-24754
4.3

This CVE describes a missing authorization vulnerability in the Houzez WordPress theme that allows unauthorized users to access functionality intended...

Jan 27, 2025
CVE-2024-12113
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete other users' reviews in the Youzify plugin. I...

Jan 25, 2025
CVE-2025-24751
4.3

This CVE describes a missing authorization vulnerability in GoDaddy's CoBlocks WordPress plugin that allows attackers to bypass access controls. It af...

Jan 24, 2025
CVE-2025-24725
4.3

This CVE describes a missing authorization vulnerability in the ThimPress Thim Elementor Kit WordPress plugin that allows attackers to exploit incorre...

Jan 24, 2025
CVE-2025-24693
4.3

This CVE describes a missing authorization vulnerability in the Yehi Advanced Notifications WordPress plugin that allows attackers to exploit incorrec...

Jan 24, 2025
CVE-2025-24679
4.3

This CVE describes a missing authorization vulnerability in the WordPress Internal Links Manager plugin (also called SEO Automated Link Building) that...

Jan 24, 2025
CVE-2025-24682
4.3

This CVE describes a missing authorization vulnerability in the Super Block Slider WordPress plugin that allows attackers to bypass access controls. I...

Jan 24, 2025
CVE-2025-24618
4.3

This CVE describes a missing authorization vulnerability in ElementInvader Addons for Elementor WordPress plugin that allows attackers to bypass inten...

Jan 24, 2025
CVE-2025-24591
4.3

This CVE describes a missing authorization vulnerability in the NinjaTeam GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypas...

Jan 24, 2025
CVE-2024-12879
4.3

The WPBot Pro WordPress Chatbot plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to cr...

Jan 22, 2025
CVE-2025-22721
4.3

This CVE describes a missing authorization vulnerability in the ApplyOnline WordPress plugin that allows attackers to bypass access controls. It affec...

Jan 21, 2025
CVE-2025-23954
4.3

This CVE describes a missing authorization vulnerability in the Salvador AI Image Generator WordPress plugin that allows attackers to bypass access co...

Jan 16, 2025
CVE-2025-23957
4.3

This CVE describes a Missing Authorization vulnerability in the Sur.ly WordPress plugin that allows attackers to exploit incorrectly configured access...

Jan 16, 2025
CVE-2025-23962
4.3

This CVE describes a Missing Authorization vulnerability in the Goldstar WordPress plugin that allows attackers to bypass access controls. Attackers c...

Jan 16, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,074 CVEs classified as CWE-862, with 231 rated critical and 874 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free