CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,077)
This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view revision history of posts and pages, potentiall...
Nov 20, 2024This vulnerability allows unauthorized users to exploit incorrectly configured access controls in the Easy Accordion Gutenberg Block WordPress plugin....
Nov 19, 2024This CVE describes a Missing Authorization vulnerability in the Rextheme WP VR WordPress plugin that allows attackers to exploit incorrectly configure...
Nov 19, 2024This CVE describes a Missing Authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass intended access c...
Nov 19, 2024The WP Chat App WordPress plugin allows authenticated attackers with Subscriber-level access or higher to install the filebird plugin without proper a...
Nov 16, 2024The Tutor LMS Elementor Addons WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher ...
Nov 15, 2024This vulnerability in Jenkins Script Security Plugin allows attackers with Overall/Read permission to check for the existence of files on the Jenkins ...
Nov 13, 2024The Buy one click WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or high...
Nov 13, 2024The Buy one click WooCommerce WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or high...
Nov 13, 2024The Tumult Hype Animations WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher ...
Nov 6, 2024This CVE describes a Missing Authorization vulnerability in the Happy Addons for Elementor WordPress plugin. It allows attackers to exploit incorrectl...
Nov 1, 2024CubeWP WordPress plugin versions up to 1.1.15 have a missing authorization vulnerability that allows attackers to bypass access controls and potential...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Magazine3 PWA for WP & AMP WordPress plugin that allows attackers to exploit incorrect...
Nov 1, 2024CVE-2024-44052 is a missing authorization vulnerability in the HelloAsso WordPress plugin that allows attackers to bypass access controls and perform ...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the WooCommerce Multilingual & Multicurrency WordPress plugin that allows attackers to exp...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the WP Free SSL WordPress plugin. It allows attackers to perform actions without proper au...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the BearDev JoomSport WordPress plugin that allows attackers to bypass access controls. It...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the GeoDirectory WordPress plugin that allows attackers to bypass access controls. It affe...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the GetPaid WordPress plugin that allows attackers to bypass access controls and perform u...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Order Tracking WordPress plugin that allows unauthorized users to access functionality...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Envira Photo Gallery WordPress plugin that allows attackers to bypass access controls....
Nov 1, 2024This vulnerability allows attackers to bypass authorization controls in the Asset CleanUp: Page Speed Booster WordPress plugin, potentially accessing ...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Jordy Meow Photo Engine WordPress plugin that allows attackers to bypass access contro...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Clone plugin (Migrate Clone) that allows attackers to exploit incorrectly co...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Flash & HTML5 Video plugin by bPlugins LLC. It allows attackers to bypass ac...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in Zaytech's Smart Online Order for Clover WordPress plugin. It allows attackers to bypass ac...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the WP Search Analytics WordPress plugin that allows attackers to exploit incorrectly conf...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Easy Digital Downloads WordPress plugin that allows attackers to bypass access control...
Nov 1, 2024This vulnerability allows unauthorized users to access administrative functions in the Advanced Cron Manager WordPress plugin due to missing authoriza...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin that allows attackers to exploit incorrectly conf...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls. ...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Seraphinite Post .DOCX Source WordPress plugin that allows attackers to exploit incorr...
Nov 1, 2024CVE-2024-38714 is a missing authorization vulnerability in the WP Fast Total Search WordPress plugin that allows attackers to bypass access controls a...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Brainstorm Force Spectra WordPress plugin, allowing attackers to exploit incorrectly c...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Post Grid WordPress plugin by RadiusTheme, allowing exploitation of incorrectly config...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Business One Page WordPress theme that allows attackers to exploit incorrectly configu...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the Church Admin WordPress plugin that allows attackers to bypass access controls and perf...
Nov 1, 2024This CVE describes a missing authorization vulnerability in the WordPress Page Builder Sandwich plugin that allows attackers to exploit incorrectly co...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the PropertyHive WordPress plugin that allows attackers to exploit incorrectly configured ...
Nov 1, 2024This CVE describes a Missing Authorization vulnerability in the Woocommerce Customers Order History WordPress plugin that allows attackers to bypass a...
Nov 1, 2024This vulnerability allows attackers to bypass authorization controls in Envira Photo Gallery WordPress plugin, potentially enabling unauthorized actio...
Nov 1, 2024The Download Monitor WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to ret...
Oct 30, 2024This CVE describes a Missing Authorization vulnerability in Mondula GmbH's Multi Step Form WordPress plugin that allows attackers to bypass access con...
Oct 29, 2024This vulnerability in JetBrains Hub allows authenticated users to generate permanent authentication tokens for services they shouldn't have access to....
Oct 28, 2024The Download Monitor WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher t...
Oct 26, 2024The Editorial Assistant by Sovrn WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or h...
Oct 26, 2024The WooCommerce UPS Shipping plugin for WordPress has a missing capability check that allows authenticated users with Subscriber-level access or highe...
Oct 25, 2024ProfileGrid WordPress plugin versions up to 5.9.3 have a missing authorization vulnerability that allows attackers to perform unauthorized actions. Th...
Oct 21, 2024This vulnerability allows unauthorized users to modify post ordering in WordPress sites using the Simple Custom Post Order plugin. Attackers can explo...
Oct 21, 2024This vulnerability allows subscribers (low-privileged users) in WordPress to dismiss admin notices they shouldn't have access to, due to broken access...
Oct 20, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,077 CVEs classified as CWE-862, with 231 rated critical and 877 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free