CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,076)
This CVE describes a missing authorization vulnerability in SolidWP iThemes Sync WordPress plugin that allows attackers to bypass access controls. It ...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the QR code MeCard/vCard generator WordPress plugin that allows unauthorized users to acce...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the WordPress Quiz And Survey Master plugin that allows attackers to bypass access control...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the Inisev Social Media & Share Icons WordPress plugin that allows attackers to exploit in...
Dec 13, 2024This vulnerability allows authenticated WordPress users to activate arbitrary plugins without proper authorization in the Viral Mag theme. It affects ...
Dec 13, 2024CVE-2022-47176 is a missing authorization vulnerability in the Depicter Slider WordPress plugin that allows attackers to exploit incorrectly configure...
Dec 13, 2024CVE-2022-46811 is a missing authorization vulnerability in the ALD Dropshipping plugin for WordPress that allows attackers to exploit incorrectly conf...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the Formidable Forms WordPress plugin that allows attackers to exploit incorrectly configu...
Dec 13, 2024This CVE describes a missing authorization vulnerability in the eRoom WordPress plugin that allows attackers to bypass access controls. It affects all...
Dec 13, 2024The Hash Form WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level permissions or higher to crea...
Dec 12, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to whitelist scripts without proper authorization. Atta...
Dec 12, 2024The Child Theme Creator by Orbisius WordPress plugin's Cloud Library Addon has missing capability checks in cloud_delete() and cloud_update() function...
Dec 12, 2024The Custom Skins Contact Form 7 WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level ac...
Dec 12, 2024CVE-2024-54269 is a missing authorization vulnerability in the Notibar WordPress plugin that allows attackers to bypass access controls and perform un...
Dec 11, 2024This CVE describes a Missing Authorization vulnerability in the Dotstore Minimum and Maximum Quantity for WooCommerce plugin that allows attackers to ...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Social Media Feather WordPress plugin that allows attackers to exploit incorrectly con...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Product Filter by WBW WordPress plugin. It allows attackers to exploit incorrectly con...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Custom Login WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 9, 2024This vulnerability allows attackers to exploit missing authorization checks in the Post Duplicator WordPress plugin, enabling unauthorized users to du...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Bulk Edit Post Titles WordPress plugin that allows attackers to exploit incorrectly co...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Veribo, Roland Murg WP Booking System plugin for WordPress, allowing attackers to expl...
Dec 9, 2024This CVE describes a missing authorization vulnerability in GoDaddy's Email Marketing WordPress plugin that allows attackers to bypass access controls...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Easy Social Feed WordPress plugin that allows attackers to exploit incorrectly configu...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the Conditional Fields for Contact Form 7 WordPress plugin, potentially access...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WordPress BetterDocs plugin that allows attackers to bypass intended access controls. ...
Dec 9, 2024CVE-2023-47780 is a missing authorization vulnerability in the EasyAzon WordPress plugin that allows attackers to exploit incorrectly configured acces...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the Essential Blocks for Gutenberg WordPress plugin, potentially accessing res...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Smart WooCommerce Search WordPress plugin that allows attackers to exploit incorrectly...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Real Estate Directory WordPress theme that allows authenticated users to activate arbi...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Site Reviews plugin that allows attackers to exploit incorrectly configured ...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the Backup Bank WordPress plugin that allows attackers to bypass access controls. It affec...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Chankhe WordPress theme that allows authenticated users to activate arbitrary plugins ...
Dec 9, 2024CVE-2023-25993 is a missing authorization vulnerability in the WebberZone Top 10 WordPress plugin that allows attackers to exploit incorrectly configu...
Dec 9, 2024This CVE describes a missing authorization vulnerability in the WordPress 'We're Open!' plugin that allows attackers to bypass access controls. It aff...
Dec 9, 2024The Migrate Clone WordPress plugin versions up to 2.3.7 have a missing authorization vulnerability that allows attackers to exploit incorrectly config...
Dec 9, 2024This CVE describes a Missing Authorization vulnerability in the Clever Widgets Enhanced Text Widget WordPress plugin. It allows attackers to exploit i...
Dec 9, 2024This vulnerability allows attackers to bypass authorization controls in the Spectra WordPress plugin, potentially enabling unauthorized actions. It af...
Dec 9, 2024CVE-2023-23725 is a missing authorization vulnerability in the Shortcodes WordPress plugin that allows attackers to bypass access controls and perform...
Dec 9, 2024The SMS for Lead Capture Forms WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or hig...
Dec 7, 2024The Message Filter for Contact Form 7 WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access...
Dec 6, 2024The Eleblog WordPress plugin has an authorization vulnerability that allows any authenticated user (including basic Subscribers) to submit plugin deac...
Dec 4, 2024This CVE describes a Missing Authorization vulnerability in the E-goi Smart Marketing SMS and Newsletters Forms WordPress plugin that allows attackers...
Dec 2, 2024This vulnerability in the WordPress Image Alt Text plugin allows authenticated attackers with subscriber-level access or higher to modify alt text on ...
Nov 28, 2024The Hustle WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view unpublis...
Nov 26, 2024The WPDash Notes WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to view co...
Nov 23, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to add or remove custom sidebars when the Carbon Fields...
Nov 23, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view playlist settings without proper authorization....
Nov 22, 2024This vulnerability in the Ultimate YouTube Video & Shorts Player With Vimeo WordPress plugin allows authenticated attackers with Subscriber-level acce...
Nov 21, 2024This vulnerability in the Ultimate Member WordPress plugin allows authenticated attackers with subscriber-level access or higher to change other users...
Nov 21, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view revision history of posts and pages, potentiall...
Nov 20, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,076 CVEs classified as CWE-862, with 231 rated critical and 876 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free