CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,074)
This CVE describes a missing authorization vulnerability in the sourceplay-navermap WordPress plugin that allows attackers to bypass access controls. ...
Mar 24, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to approve or decline group join requests, which should...
Mar 22, 2025This vulnerability in open-webui v0.3.8 allows attackers to bypass access controls and view all prompts created by administrators. Attackers can retri...
Mar 20, 2025The WPSchoolPress WordPress plugin has a missing capability check that allows authenticated users with teacher-level access or higher to delete any us...
Mar 15, 2025The Zegen Church WordPress theme has missing capability checks on AJAX endpoints, allowing authenticated users with Subscriber-level access or higher ...
Mar 14, 2025This vulnerability in the Pagelayer WordPress plugin allows authenticated users with Contributor-level access or higher to bypass post moderation and ...
Mar 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to enable/disable plugin widgets without proper authori...
Mar 13, 2025This CVE describes a missing authorization vulnerability in the WP Performance Pack WordPress plugin that allows attackers to exploit incorrectly conf...
Mar 11, 2025This vulnerability in SAP's Manage Purchasing Info Records OData service allows authenticated users to escalate privileges due to missing authorizatio...
Mar 11, 2025An authenticated low-privilege user can exploit a missing authorization check in the IBS module of FS-RBD to perform unauthorized actions beyond their...
Mar 11, 2025The Post Lockdown WordPress plugin has an information exposure vulnerability that allows authenticated users with Subscriber-level access or higher to...
Mar 8, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to import demo content and overwrite the site through A...
Mar 5, 2025The VW Storefront WordPress theme has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher ...
Mar 4, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify plugin page settings without proper authoriza...
Mar 1, 2025The Forex Calculators WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher ...
Feb 28, 2025This CVE describes a broken authorization vulnerability where authenticated users can download IOA script and configuration files by knowing specific ...
Feb 26, 2025This CVE describes a Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for WordPress that allows unauthorized users to access functiona...
Feb 25, 2025This CVE describes a Missing Authorization vulnerability in WPDeveloper's Essential Blocks for Gutenberg WordPress plugin. It allows attackers to expl...
Feb 25, 2025The Team Builder WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify ...
Feb 18, 2025The Team – Team Members Showcase Plugin for WordPress has a missing capability check in its response() function, allowing authenticated attackers wi...
Feb 15, 2025The Read More & Accordion WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher t...
Feb 13, 2025This vulnerability allows authenticated low-privileged attackers to create arbitrary user groups in Q-Free MaxTime traffic management systems. Attacke...
Feb 12, 2025The WP Table Manager WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to rea...
Feb 12, 2025This CVE describes an authorization bypass vulnerability in SAP systems where authenticated users can access unauthorized data through a remote-enable...
Feb 11, 2025This vulnerability allows banned group members to access updates to issues via the GitLab API, potentially exposing sensitive information about issue ...
Feb 5, 2025A missing authorization vulnerability in the FameThemes OnePress WordPress theme allows attackers to bypass access controls and potentially modify the...
Feb 4, 2025The Eventer WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level permissions or higher to downloa...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in the Hide Shipping Method For WooCommerce plugin that allows unauthorized users to access f...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in the Xfinity Soft Content Cloner WordPress plugin that allows attackers to exploit incorrec...
Feb 3, 2025This CVE describes a Missing Authorization vulnerability in the Shortcodes and extra features for Phlox theme WordPress plugin. It allows attackers to...
Feb 3, 2025This vulnerability in the WordPress Login Page Styler plugin allows authenticated attackers with Subscriber-level access or higher to delete login log...
Jan 31, 2025The Food Menu plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or higher to modify plu...
Jan 31, 2025This vulnerability allows authenticated WordPress users with subscriber-level access or higher to enable or disable widgets without proper authorizati...
Jan 31, 2025The zStore Manager Basic WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or...
Jan 30, 2025The ECPay Ecommerce for WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access o...
Jan 30, 2025CVE-2025-24744 is a missing authorization vulnerability in the Bridge Core WordPress plugin that allows attackers to bypass access controls. This affe...
Jan 27, 2025This CVE describes a missing authorization vulnerability in the Houzez WordPress theme that allows unauthorized users to access functionality intended...
Jan 27, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete other users' reviews in the Youzify plugin. I...
Jan 25, 2025This CVE describes a missing authorization vulnerability in GoDaddy's CoBlocks WordPress plugin that allows attackers to bypass access controls. It af...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the ThimPress Thim Elementor Kit WordPress plugin that allows attackers to exploit incorre...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the Yehi Advanced Notifications WordPress plugin that allows attackers to exploit incorrec...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the WordPress Internal Links Manager plugin (also called SEO Automated Link Building) that...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the Super Block Slider WordPress plugin that allows attackers to bypass access controls. I...
Jan 24, 2025This CVE describes a missing authorization vulnerability in ElementInvader Addons for Elementor WordPress plugin that allows attackers to bypass inten...
Jan 24, 2025This CVE describes a missing authorization vulnerability in the NinjaTeam GDPR CCPA Compliance Support WordPress plugin that allows attackers to bypas...
Jan 24, 2025The WPBot Pro WordPress Chatbot plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to cr...
Jan 22, 2025This CVE describes a missing authorization vulnerability in the ApplyOnline WordPress plugin that allows attackers to bypass access controls. It affec...
Jan 21, 2025This CVE describes a missing authorization vulnerability in the Salvador AI Image Generator WordPress plugin that allows attackers to bypass access co...
Jan 16, 2025This CVE describes a Missing Authorization vulnerability in the Sur.ly WordPress plugin that allows attackers to exploit incorrectly configured access...
Jan 16, 2025This CVE describes a Missing Authorization vulnerability in the Goldstar WordPress plugin that allows attackers to bypass access controls. Attackers c...
Jan 16, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,074 CVEs classified as CWE-862, with 231 rated critical and 874 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free