CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,077
Total CVEs
231
Critical
877
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
441
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 127
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,077)

CVE-2024-11154
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view revision history of posts and pages, potentiall...

Nov 20, 2024
CVE-2024-51660
4.3

This vulnerability allows unauthorized users to exploit incorrectly configured access controls in the Easy Accordion Gutenberg Block WordPress plugin....

Nov 19, 2024
CVE-2024-49680
4.3

This CVE describes a Missing Authorization vulnerability in the Rextheme WP VR WordPress plugin that allows attackers to exploit incorrectly configure...

Nov 19, 2024
CVE-2024-49697
4.3

This CVE describes a Missing Authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass intended access c...

Nov 19, 2024
CVE-2024-10533
4.3

The WP Chat App WordPress plugin allows authenticated attackers with Subscriber-level access or higher to install the filebird plugin without proper a...

Nov 16, 2024
CVE-2024-10897
4.3

The Tutor LMS Elementor Addons WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher ...

Nov 15, 2024
CVE-2024-52549
4.3

This vulnerability in Jenkins Script Security Plugin allows attackers with Overall/Read permission to check for the existence of files on the Jenkins ...

Nov 13, 2024
CVE-2024-10852
4.3

The Buy one click WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or high...

Nov 13, 2024
CVE-2024-10854
4.3

The Buy one click WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or high...

Nov 13, 2024
CVE-2024-10543
4.3

The Tumult Hype Animations WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher ...

Nov 6, 2024
CVE-2024-48045
4.3

This CVE describes a Missing Authorization vulnerability in the Happy Addons for Elementor WordPress plugin. It allows attackers to exploit incorrectl...

Nov 1, 2024
CVE-2024-48039
4.3

CubeWP WordPress plugin versions up to 1.1.15 have a missing authorization vulnerability that allows attackers to bypass access controls and potential...

Nov 1, 2024
CVE-2024-47318
4.3

This CVE describes a Missing Authorization vulnerability in the Magazine3 PWA for WP & AMP WordPress plugin that allows attackers to exploit incorrect...

Nov 1, 2024
CVE-2024-44052
4.3

CVE-2024-44052 is a missing authorization vulnerability in the HelloAsso WordPress plugin that allows attackers to bypass access controls and perform ...

Nov 1, 2024
CVE-2024-44006
4.3

This CVE describes a missing authorization vulnerability in the WooCommerce Multilingual & Multicurrency WordPress plugin that allows attackers to exp...

Nov 1, 2024
CVE-2024-44020
4.3

This CVE describes a Missing Authorization vulnerability in the WP Free SSL WordPress plugin. It allows attackers to perform actions without proper au...

Nov 1, 2024
CVE-2024-44031
4.3

This CVE describes a Missing Authorization vulnerability in the BearDev JoomSport WordPress plugin that allows attackers to bypass access controls. It...

Nov 1, 2024
CVE-2024-43981
4.3

This CVE describes a missing authorization vulnerability in the GeoDirectory WordPress plugin that allows attackers to bypass access controls. It affe...

Nov 1, 2024
CVE-2024-43973
4.3

This CVE describes a missing authorization vulnerability in the GetPaid WordPress plugin that allows attackers to bypass access controls and perform u...

Nov 1, 2024
CVE-2024-43343
4.3

This CVE describes a Missing Authorization vulnerability in the Order Tracking WordPress plugin that allows unauthorized users to access functionality...

Nov 1, 2024
CVE-2024-43925
4.3

This CVE describes a missing authorization vulnerability in the Envira Photo Gallery WordPress plugin that allows attackers to bypass access controls....

Nov 1, 2024
CVE-2024-43314
4.3

This vulnerability allows attackers to bypass authorization controls in the Asset CleanUp: Page Speed Booster WordPress plugin, potentially accessing ...

Nov 1, 2024
CVE-2024-43332
4.3

This CVE describes a Missing Authorization vulnerability in the Jordy Meow Photo Engine WordPress plugin that allows attackers to bypass access contro...

Nov 1, 2024
CVE-2024-43298
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Clone plugin (Migrate Clone) that allows attackers to exploit incorrectly co...

Nov 1, 2024
CVE-2024-43296
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Flash & HTML5 Video plugin by bPlugins LLC. It allows attackers to bypass ac...

Nov 1, 2024
CVE-2024-43254
4.3

This CVE describes a Missing Authorization vulnerability in Zaytech's Smart Online Order for Clover WordPress plugin. It allows attackers to bypass ac...

Nov 1, 2024
CVE-2024-43229
4.3

This CVE describes a Missing Authorization vulnerability in the WP Search Analytics WordPress plugin that allows attackers to exploit incorrectly conf...

Nov 1, 2024
CVE-2024-43162
4.3

This CVE describes a missing authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to bypass access control...

Nov 1, 2024
CVE-2024-43154
4.3

This vulnerability allows unauthorized users to access administrative functions in the Advanced Cron Manager WordPress plugin due to missing authoriza...

Nov 1, 2024
CVE-2024-43119
4.3

This CVE describes a Missing Authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin that allows attackers to exploit incorrectly conf...

Nov 1, 2024
CVE-2024-43136
4.3

This CVE describes a Missing Authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls. ...

Nov 1, 2024
CVE-2024-38727
4.3

This CVE describes a Missing Authorization vulnerability in the Seraphinite Post .DOCX Source WordPress plugin that allows attackers to exploit incorr...

Nov 1, 2024
CVE-2024-38714
4.3

CVE-2024-38714 is a missing authorization vulnerability in the WP Fast Total Search WordPress plugin that allows attackers to bypass access controls a...

Nov 1, 2024
CVE-2024-37517
4.3

This CVE describes a Missing Authorization vulnerability in the Brainstorm Force Spectra WordPress plugin, allowing attackers to exploit incorrectly c...

Nov 1, 2024
CVE-2024-37482
4.3

This CVE describes a Missing Authorization vulnerability in the Post Grid WordPress plugin by RadiusTheme, allowing exploitation of incorrectly config...

Nov 1, 2024
CVE-2024-37505
4.3

This CVE describes a missing authorization vulnerability in the Business One Page WordPress theme that allows attackers to exploit incorrectly configu...

Nov 1, 2024
CVE-2024-37440
4.3

This CVE describes a missing authorization vulnerability in the Church Admin WordPress plugin that allows attackers to bypass access controls and perf...

Nov 1, 2024
CVE-2024-37218
4.3

This CVE describes a missing authorization vulnerability in the WordPress Page Builder Sandwich plugin that allows attackers to exploit incorrectly co...

Nov 1, 2024
CVE-2024-37204
4.3

This CVE describes a Missing Authorization vulnerability in the PropertyHive WordPress plugin that allows attackers to exploit incorrectly configured ...

Nov 1, 2024
CVE-2024-37201
4.3

This CVE describes a Missing Authorization vulnerability in the Woocommerce Customers Order History WordPress plugin that allows attackers to bypass a...

Nov 1, 2024
CVE-2024-37095
4.3

This vulnerability allows attackers to bypass authorization controls in Envira Photo Gallery WordPress plugin, potentially enabling unauthorized actio...

Nov 1, 2024
CVE-2024-10399
4.3

The Download Monitor WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to ret...

Oct 30, 2024
CVE-2024-50428
4.3

This CVE describes a Missing Authorization vulnerability in Mondula GmbH's Multi Step Form WordPress plugin that allows attackers to bypass access con...

Oct 29, 2024
CVE-2024-50573
4.3

This vulnerability in JetBrains Hub allows authenticated users to generate permanent authentication tokens for services they shouldn't have access to....

Oct 28, 2024
CVE-2024-10092
4.3

The Download Monitor WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher t...

Oct 26, 2024
CVE-2024-9626
4.3

The Editorial Assistant by Sovrn WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or h...

Oct 26, 2024
CVE-2024-9109
4.3

The WooCommerce UPS Shipping plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or highe...

Oct 25, 2024
CVE-2024-49273
4.3

ProfileGrid WordPress plugin versions up to 5.9.3 have a missing authorization vulnerability that allows attackers to perform unauthorized actions. Th...

Oct 21, 2024
CVE-2024-49321
4.3

This vulnerability allows unauthorized users to modify post ordering in WordPress sites using the Simple Custom Post Order plugin. Attackers can explo...

Oct 21, 2024
CVE-2024-49325
4.3

This vulnerability allows subscribers (low-privileged users) in WordPress to dismiss admin notices they shouldn't have access to, due to broken access...

Oct 20, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,077 CVEs classified as CWE-862, with 231 rated critical and 877 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free