CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,074
Total CVEs
231
Critical
874
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
441
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 126
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,074)

CVE-2025-23929
4.3

This CVE describes a Missing Authorization vulnerability in the wishfulthemes Email Capture & Lead Generation WordPress plugin that allows attackers t...

Jan 16, 2025
CVE-2025-23785
4.3

This CVE describes a missing authorization vulnerability in the August Infotech AI Responsive Gallery Album WordPress plugin. It allows attackers to b...

Jan 16, 2025
CVE-2025-23423
4.3

This CVE describes a Missing Authorization vulnerability in the SendGrid for WordPress plugin that allows attackers to exploit incorrectly configured ...

Jan 16, 2025
CVE-2025-22787
4.3

This CVE describes a missing authorization vulnerability in the Button Block WordPress plugin that allows attackers to access functionality not proper...

Jan 15, 2025
CVE-2025-22779
4.3

This CVE describes a Missing Authorization vulnerability in the WP News Sliders WordPress plugin that allows attackers to exploit incorrectly configur...

Jan 15, 2025
CVE-2024-11851
4.3

The NitroPack WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to modify arb...

Jan 15, 2025
CVE-2025-0068
4.3

CVE-2025-0068 is an authorization bypass vulnerability in SAP NetWeaver Application Server ABAP where obsolete functionality lacks proper access contr...

Jan 14, 2025
CVE-2025-22561
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Title Experiments Free plugin that allows attackers to bypass access control...

Jan 9, 2025
CVE-2024-12431
4.3

This vulnerability allows unauthorized users to manipulate the status of issues in public GitLab projects. It affects GitLab Community Edition (CE) an...

Jan 8, 2025
CVE-2025-22319
4.3

This CVE describes a Missing Authorization vulnerability in the MashShare WordPress plugin that allows unauthorized users to perform actions intended ...

Jan 7, 2025
CVE-2025-22591
4.3

This CVE describes a missing authorization vulnerability in the Lenderd 1003 Mortgage Application WordPress plugin that allows unauthorized users to a...

Jan 7, 2025
CVE-2025-22299
4.3

This CVE describes a Missing Authorization vulnerability in the spacecodes AI for SEO WordPress plugin that allows attackers to exploit incorrectly co...

Jan 7, 2025
CVE-2024-56276
4.3

This CVE describes a missing authorization vulnerability in WPForms Contact Form plugin that allows attackers to bypass access controls and perform un...

Jan 7, 2025
CVE-2024-56271
4.3

This vulnerability allows attackers to bypass authorization controls in the WP SecureSubmit WordPress plugin, potentially accessing functionality or d...

Jan 7, 2025
CVE-2024-10536
4.3

The FancyPost WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to export sho...

Jan 7, 2025
CVE-2023-47807
4.3

This CVE describes a missing authorization vulnerability in the 10WebAnalytics WordPress plugin that allows attackers to bypass access controls. It af...

Jan 2, 2025
CVE-2022-41995
4.3

This CVE describes a missing authorization vulnerability in the Gallery Images Ape WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 2, 2025
CVE-2024-56255
4.3

This CVE describes a Missing Authorization vulnerability in the AyeCode Connect WordPress plugin that allows attackers to exploit incorrectly configur...

Jan 2, 2025
CVE-2024-56236
4.3

This CVE describes a Missing Authorization vulnerability in the Hestia Nginx Cache WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 2, 2025
CVE-2023-47692
4.3

This CVE describes a Missing Authorization vulnerability in Flothemes Flo Forms WordPress plugin that allows attackers to bypass access controls. It a...

Jan 2, 2025
CVE-2023-47557
4.3

This CVE describes a missing authorization vulnerability in the WordPress Visitors Traffic Real Time Statistics plugin that allows attackers to bypass...

Jan 2, 2025
CVE-2023-46612
4.3

This CVE describes a Missing Authorization vulnerability in the codedrafty Mediabay WordPress plugin that allows attackers to bypass access controls. ...

Jan 2, 2025
CVE-2023-46628
4.3

This CVE describes a Missing Authorization vulnerability in the WP Word Count WordPress plugin that allows attackers to exploit incorrectly configured...

Jan 2, 2025
CVE-2023-46203
4.3

This CVE describes a Missing Authorization vulnerability in the Just Custom Fields WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 2, 2025
CVE-2023-46080
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress ApplyOnline plugin that allows attackers to bypass access controls. It affec...

Jan 2, 2025
CVE-2023-45760
4.3

This CVE describes a Missing Authorization vulnerability in the wpDiscuz WordPress plugin that allows attackers to exploit incorrectly configured acce...

Jan 2, 2025
CVE-2023-45002
4.3

This CVE describes a missing authorization vulnerability in the weDevs WP User Frontend WordPress plugin that allows attackers to bypass access contro...

Jan 2, 2025
CVE-2023-45110
4.3

This CVE describes a missing authorization vulnerability in the Bold Timeline Lite WordPress plugin that allows attackers to exploit incorrectly confi...

Jan 2, 2025
CVE-2024-51667
4.3

This CVE describes a Missing Authorization vulnerability in the Paytium WordPress plugin that allows unauthorized users to access functionality intend...

Dec 31, 2024
CVE-2023-50850
4.3

This CVE describes a missing authorization vulnerability in WooCommerce Subscriptions that allows attackers to exploit incorrectly configured access c...

Dec 31, 2024
CVE-2024-56215
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Member Directory and Contact Form plugin that allows unauthorized users to a...

Dec 31, 2024
CVE-2024-56219
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Widget Options plugin that allows attackers to exploit incorrectly configure...

Dec 31, 2024
CVE-2024-12190
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view all form submissions from other users. The issu...

Dec 25, 2024
CVE-2024-12210
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to remove the shop logo from WooCommerce delivery notes...

Dec 24, 2024
CVE-2024-12331
4.3

The File Manager Pro – Filester WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level per...

Dec 19, 2024
CVE-2024-56003
4.3

CVE-2024-56003 is a missing authorization vulnerability in the Caldera SMTP Mailer WordPress plugin that allows attackers to perform unauthorized acti...

Dec 16, 2024
CVE-2024-54384
4.3

This CVE describes a missing authorization vulnerability in the Falcon WordPress plugin that allows attackers to exploit incorrectly configured access...

Dec 16, 2024
CVE-2024-54298
4.3

This CVE describes a Missing Authorization vulnerability in the Bill Minozzi Car Dealer WordPress plugin that allows attackers to bypass access contro...

Dec 13, 2024
CVE-2024-54268
4.3

This CVE describes a missing authorization vulnerability in the SiteOrigin Widgets Bundle WordPress plugin that allows attackers to exploit incorrectl...

Dec 13, 2024
CVE-2023-41951
4.3

This CVE describes a missing authorization vulnerability in rtMedia for WordPress, BuddyPress and bbPress that allows attackers to exploit incorrectly...

Dec 13, 2024
CVE-2023-41865
4.3

CVE-2023-41865 is a missing authorization vulnerability in the bqworks Slider Pro WordPress plugin that allows attackers to exploit incorrectly config...

Dec 13, 2024
CVE-2023-41869
4.3

This vulnerability allows attackers to bypass authorization controls in WP Accessibility Helper (WAH) WordPress plugin, potentially accessing restrict...

Dec 13, 2024
CVE-2023-41873
4.3

This vulnerability allows attackers to bypass authorization controls in the miniOrange SAML SP Single Sign On WordPress plugin, potentially accessing ...

Dec 13, 2024
CVE-2023-41802
4.3

This CVE describes a Missing Authorization vulnerability in the Team Heateor Super Socializer WordPress plugin that allows attackers to exploit incorr...

Dec 13, 2024
CVE-2023-40670
4.3

This CVE describes a Missing Authorization vulnerability in the ReviewX WordPress plugin that allows attackers to bypass access controls and perform u...

Dec 13, 2024
CVE-2023-40203
4.3

This CVE describes a Missing Authorization vulnerability in the MailChimp Forms by MailMunch WordPress plugin that allows attackers to exploit incorre...

Dec 13, 2024
CVE-2023-40331
4.3

This CVE describes a Missing Authorization vulnerability in the bqworks Accordion Slider WordPress plugin that allows attackers to exploit incorrectly...

Dec 13, 2024
CVE-2023-38514
4.3

This CVE describes a Missing Authorization vulnerability in the Social Share Icons & Social Share Buttons WordPress plugin that allows attackers to ex...

Dec 13, 2024
CVE-2023-40001
4.3

This CVE describes a missing authorization vulnerability in SolidWP iThemes Sync WordPress plugin that allows attackers to bypass access controls. It ...

Dec 13, 2024
CVE-2023-38477
4.3

This CVE describes a missing authorization vulnerability in the QR code MeCard/vCard generator WordPress plugin that allows unauthorized users to acce...

Dec 13, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,074 CVEs classified as CWE-862, with 231 rated critical and 874 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free