CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,076
Total CVEs
231
Critical
876
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
441
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 127
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,076)

CVE-2023-40001
4.3

This CVE describes a missing authorization vulnerability in SolidWP iThemes Sync WordPress plugin that allows attackers to bypass access controls. It ...

Dec 13, 2024
CVE-2023-38477
4.3

This CVE describes a missing authorization vulnerability in the QR code MeCard/vCard generator WordPress plugin that allows unauthorized users to acce...

Dec 13, 2024
CVE-2023-37984
4.3

This CVE describes a missing authorization vulnerability in the WordPress Quiz And Survey Master plugin that allows attackers to bypass access control...

Dec 13, 2024
CVE-2023-34009
4.3

This CVE describes a Missing Authorization vulnerability in the Inisev Social Media & Share Icons WordPress plugin that allows attackers to exploit in...

Dec 13, 2024
CVE-2023-28990
4.3

This vulnerability allows authenticated WordPress users to activate arbitrary plugins without proper authorization in the Viral Mag theme. It affects ...

Dec 13, 2024
CVE-2022-47176
4.3

CVE-2022-47176 is a missing authorization vulnerability in the Depicter Slider WordPress plugin that allows attackers to exploit incorrectly configure...

Dec 13, 2024
CVE-2022-46811
4.3

CVE-2022-46811 is a missing authorization vulnerability in the ALD Dropshipping plugin for WordPress that allows attackers to exploit incorrectly conf...

Dec 13, 2024
CVE-2022-45806
4.3

This CVE describes a missing authorization vulnerability in the Formidable Forms WordPress plugin that allows attackers to exploit incorrectly configu...

Dec 13, 2024
CVE-2022-43472
4.3

This CVE describes a missing authorization vulnerability in the eRoom WordPress plugin that allows attackers to bypass access controls. It affects all...

Dec 13, 2024
CVE-2024-12201
4.3

The Hash Form WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level permissions or higher to crea...

Dec 12, 2024
CVE-2024-11724
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to whitelist scripts without proper authorization. Atta...

Dec 12, 2024
CVE-2024-12263
4.3

The Child Theme Creator by Orbisius WordPress plugin's Cloud Library Addon has missing capability checks in cloud_delete() and cloud_update() function...

Dec 12, 2024
CVE-2024-12341
4.3

The Custom Skins Contact Form 7 WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level ac...

Dec 12, 2024
CVE-2024-54269
4.3

CVE-2024-54269 is a missing authorization vulnerability in the Notibar WordPress plugin that allows attackers to bypass access controls and perform un...

Dec 11, 2024
CVE-2024-54227
4.3

This CVE describes a Missing Authorization vulnerability in the Dotstore Minimum and Maximum Quantity for WooCommerce plugin that allows attackers to ...

Dec 9, 2024
CVE-2023-49861
4.3

This CVE describes a Missing Authorization vulnerability in the Social Media Feather WordPress plugin that allows attackers to exploit incorrectly con...

Dec 9, 2024
CVE-2023-50877
4.3

This CVE describes a Missing Authorization vulnerability in the Product Filter by WBW WordPress plugin. It allows attackers to exploit incorrectly con...

Dec 9, 2024
CVE-2023-49858
4.3

This CVE describes a missing authorization vulnerability in the Custom Login WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 9, 2024
CVE-2023-49835
4.3

This vulnerability allows attackers to exploit missing authorization checks in the Post Duplicator WordPress plugin, enabling unauthorized users to du...

Dec 9, 2024
CVE-2023-49754
4.3

This CVE describes a Missing Authorization vulnerability in the Bulk Edit Post Titles WordPress plugin that allows attackers to exploit incorrectly co...

Dec 9, 2024
CVE-2023-49758
4.3

This CVE describes a Missing Authorization vulnerability in the Veribo, Roland Murg WP Booking System plugin for WordPress, allowing attackers to expl...

Dec 9, 2024
CVE-2023-49156
4.3

This CVE describes a missing authorization vulnerability in GoDaddy's Email Marketing WordPress plugin that allows attackers to bypass access controls...

Dec 9, 2024
CVE-2023-48740
4.3

This CVE describes a Missing Authorization vulnerability in the Easy Social Feed WordPress plugin that allows attackers to exploit incorrectly configu...

Dec 9, 2024
CVE-2023-47838
4.3

This vulnerability allows attackers to bypass authorization controls in the Conditional Fields for Contact Form 7 WordPress plugin, potentially access...

Dec 9, 2024
CVE-2023-47762
4.3

This CVE describes a missing authorization vulnerability in the WordPress BetterDocs plugin that allows attackers to bypass intended access controls. ...

Dec 9, 2024
CVE-2023-47780
4.3

CVE-2023-47780 is a missing authorization vulnerability in the EasyAzon WordPress plugin that allows attackers to exploit incorrectly configured acces...

Dec 9, 2024
CVE-2023-47760
4.3

This vulnerability allows attackers to bypass authorization controls in the Essential Blocks for Gutenberg WordPress plugin, potentially accessing res...

Dec 9, 2024
CVE-2023-30783
4.3

This CVE describes a Missing Authorization vulnerability in the Smart WooCommerce Search WordPress plugin that allows attackers to exploit incorrectly...

Dec 9, 2024
CVE-2023-28532
4.3

This CVE describes a missing authorization vulnerability in the Real Estate Directory WordPress theme that allows authenticated users to activate arbi...

Dec 9, 2024
CVE-2023-27625
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Site Reviews plugin that allows attackers to exploit incorrectly configured ...

Dec 9, 2024
CVE-2023-28165
4.3

This CVE describes a missing authorization vulnerability in the Backup Bank WordPress plugin that allows attackers to bypass access controls. It affec...

Dec 9, 2024
CVE-2023-28416
4.3

This CVE describes a Missing Authorization vulnerability in the Chankhe WordPress theme that allows authenticated users to activate arbitrary plugins ...

Dec 9, 2024
CVE-2023-25993
4.3

CVE-2023-25993 is a missing authorization vulnerability in the WebberZone Top 10 WordPress plugin that allows attackers to exploit incorrectly configu...

Dec 9, 2024
CVE-2023-25067
4.3

This CVE describes a missing authorization vulnerability in the WordPress 'We're Open!' plugin that allows attackers to bypass access controls. It aff...

Dec 9, 2024
CVE-2023-25486
4.3

The Migrate Clone WordPress plugin versions up to 2.3.7 have a missing authorization vulnerability that allows attackers to exploit incorrectly config...

Dec 9, 2024
CVE-2023-23823
4.3

This CVE describes a Missing Authorization vulnerability in the Clever Widgets Enhanced Text Widget WordPress plugin. It allows attackers to exploit i...

Dec 9, 2024
CVE-2023-23834
4.3

This vulnerability allows attackers to bypass authorization controls in the Spectra WordPress plugin, potentially enabling unauthorized actions. It af...

Dec 9, 2024
CVE-2023-23725
4.3

CVE-2023-23725 is a missing authorization vulnerability in the Shortcodes WordPress plugin that allows attackers to bypass access controls and perform...

Dec 9, 2024
CVE-2024-11353
4.3

The SMS for Lead Capture Forms WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or hig...

Dec 7, 2024
CVE-2024-12027
4.3

The Message Filter for Contact Form 7 WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access...

Dec 6, 2024
CVE-2024-10663
4.3

The Eleblog WordPress plugin has an authorization vulnerability that allows any authenticated user (including basic Subscribers) to submit plugin deac...

Dec 4, 2024
CVE-2024-53784
4.3

This CVE describes a Missing Authorization vulnerability in the E-goi Smart Marketing SMS and Newsletters Forms WordPress plugin that allows attackers...

Dec 2, 2024
CVE-2024-11918
4.3

This vulnerability in the WordPress Image Alt Text plugin allows authenticated attackers with subscriber-level access or higher to modify alt text on ...

Nov 28, 2024
CVE-2024-10579
4.3

The Hustle WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view unpublis...

Nov 26, 2024
CVE-2024-9223
4.3

The WPDash Notes WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view co...

Nov 23, 2024
CVE-2024-10216
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to add or remove custom sidebars when the Carbon Fields...

Nov 23, 2024
CVE-2024-11355
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view playlist settings without proper authorization....

Nov 22, 2024
CVE-2024-11354
4.3

This vulnerability in the Ultimate YouTube Video & Shorts Player With Vimeo WordPress plugin allows authenticated attackers with Subscriber-level acce...

Nov 21, 2024
CVE-2024-10528
4.3

This vulnerability in the Ultimate Member WordPress plugin allows authenticated attackers with subscriber-level access or higher to change other users...

Nov 21, 2024
CVE-2024-11154
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view revision history of posts and pages, potentiall...

Nov 20, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,076 CVEs classified as CWE-862, with 231 rated critical and 876 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free