CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

2,994
Total CVEs
212
Critical
816
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Oracle 9

All Missing Authorization CVEs (2,994)

CVE-2025-68608
8.8

This CVE describes a Missing Authorization vulnerability in the Userpro WordPress plugin by DeluxeThemes. It allows attackers to bypass access control...

Dec 24, 2025
CVE-2025-68596
8.8

This CVE describes a Missing Authorization vulnerability in the Bit Assist WordPress plugin that allows attackers to bypass access controls. It affect...

Dec 24, 2025
CVE-2025-68592
8.8

This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls. It affec...

Dec 24, 2025
CVE-2025-68593
8.8

This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls and perfo...

Dec 24, 2025
CVE-2025-68595
8.8

This CVE describes a Missing Authorization vulnerability in the Trustindex Widgets for Social Photo Feed WordPress plugin. It allows attackers to expl...

Dec 24, 2025
CVE-2025-68582
8.8

This CVE describes a Missing Authorization vulnerability in the Funnelforms Free WordPress plugin that allows attackers to bypass access controls. Att...

Dec 24, 2025
CVE-2025-68585
8.8

This CVE describes a missing authorization vulnerability in the WP Document Revisions WordPress plugin that allows attackers to bypass access controls...

Dec 24, 2025
CVE-2025-68586
8.8

This CVE describes a missing authorization vulnerability in the Cooked WordPress plugin that allows attackers to bypass access controls. It affects al...

Dec 24, 2025
CVE-2025-68571
8.8

This CVE describes a Missing Authorization vulnerability in the SALESmanago WordPress plugin that allows attackers to bypass access controls. It affec...

Dec 24, 2025
CVE-2025-68572
8.8

This CVE describes a Missing Authorization vulnerability in the Spider Themes BBP Core WordPress plugin that allows attackers to bypass access control...

Dec 24, 2025
CVE-2025-68575
8.8

This CVE describes a Missing Authorization vulnerability in the Wappointment WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 24, 2025
CVE-2025-68577
8.8

This CVE describes a missing authorization vulnerability in the Virusdie WordPress plugin that allows attackers to bypass access controls. Attackers c...

Dec 24, 2025
CVE-2025-68569
8.8

This CVE describes a Missing Authorization vulnerability in the WP Time Slots Booking Form WordPress plugin that allows attackers to bypass access con...

Dec 24, 2025
CVE-2025-68521
8.8

This CVE describes a Missing Authorization vulnerability in the WpStream WordPress plugin that allows attackers to bypass access controls and perform ...

Dec 24, 2025
CVE-2025-68522
8.8

This CVE describes a Missing Authorization vulnerability in the WpStream WordPress plugin that allows attackers to bypass access controls and perform ...

Dec 24, 2025
CVE-2025-68505
8.8

This CVE describes a missing authorization vulnerability in the icc0rz H5P WordPress plugin that allows attackers to bypass access controls. It affect...

Dec 24, 2025
CVE-2025-14364
8.8

The Demo Importer Plus WordPress plugin has a critical vulnerability that allows authenticated attackers with Subscriber-level access or higher to tri...

Dec 18, 2025
CVE-2025-14397
8.8

The Postem Ipsum WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher to c...

Dec 13, 2025
CVE-2021-47701
8.8

CVE-2021-47701 is a privilege escalation vulnerability in OpenBMCS 2.4 that allows authenticated users with read-only permissions to elevate their pri...

Dec 9, 2025
CVE-2025-66530
8.8

This CVE describes a missing authorization vulnerability in the Webba Booking WordPress plugin that allows attackers to bypass access controls. Attack...

Dec 9, 2025
CVE-2025-66532
8.8

This CVE describes a Missing Authorization vulnerability in Mikado-Themes Powerlift WordPress theme that allows attackers to bypass access controls. I...

Dec 9, 2025
CVE-2025-66534
8.8

This CVE describes a Missing Authorization vulnerability in the Elated-Themes The Aisle WordPress theme that allows attackers to bypass access control...

Dec 9, 2025
CVE-2025-64254
8.8

This CVE describes a missing authorization vulnerability in the WordPress Photo Block plugin that allows attackers to bypass access controls. Attacker...

Dec 9, 2025
CVE-2025-62151
8.8

This CVE describes a Missing Authorization vulnerability in the Virtuaria PagBank/PagSeguro para Woocommerce WordPress plugin that allows attackers to...

Dec 9, 2025
CVE-2025-62152
8.8

This CVE describes a Missing Authorization vulnerability in the ConveyThis WordPress translation plugin that allows attackers to bypass access control...

Dec 9, 2025
CVE-2025-62153
8.8

This CVE describes a missing authorization vulnerability in the WordPress Quick Interest Slider plugin that allows attackers to bypass access controls...

Dec 9, 2025
CVE-2025-11985
8.8

The Realty Portal WordPress plugin versions 0.1 to 0.4.1 contain a missing capability check vulnerability that allows authenticated users with Subscri...

Nov 21, 2025
CVE-2025-5803
8.8

This CVE describes a Missing Authorization vulnerability in the VikBooking Hotel Booking Engine & PMS WordPress plugin. It allows attackers to bypass ...

Nov 6, 2025
CVE-2025-53246
8.8

This CVE describes a missing authorization vulnerability in the WordPress Backup and Move plugin that allows attackers to bypass access controls. Atta...

Nov 6, 2025
CVE-2025-49394
8.8

This CVE describes a Missing Authorization vulnerability in the bPlugins Image Gallery WordPress plugin (versions up to 1.0.7). It allows attackers to...

Nov 6, 2025
CVE-2025-10896
8.8

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to install arbitrary plugin packages from crafted URLs,...

Nov 4, 2025
CVE-2025-64349
8.8

CVE-2025-64349 is an access control vulnerability in ELOG that allows authenticated users to modify other users' profiles. An attacker can change a ta...

Oct 31, 2025
CVE-2023-7317
8.8

Nagios XI versions before 2024R1 have a missing access control vulnerability in the Web SSH Terminal. Remote attackers with low privileges can access ...

Oct 30, 2025
CVE-2025-62980
8.8

This CVE describes a Missing Authorization vulnerability in the MDZ Persian Admin Fonts WordPress plugin that allows attackers to bypass access contro...

Oct 27, 2025
CVE-2025-62952
8.8

This CVE describes a missing authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....

Oct 27, 2025
CVE-2025-62954
8.8

This CVE describes a missing authorization vulnerability in the Revive Old Posts WordPress plugin (also known as tweet-old-post) that allows attackers...

Oct 27, 2025
CVE-2025-62946
8.8

This CVE describes a Missing Authorization vulnerability in the Everest Backup WordPress plugin that allows attackers to bypass access controls and po...

Oct 27, 2025
CVE-2025-62924
8.8

This vulnerability allows attackers to bypass authorization controls in the Post Grid and Gutenberg Blocks WordPress plugin, potentially accessing or ...

Oct 27, 2025
CVE-2025-62929
8.8

This CVE describes a Missing Authorization vulnerability in the WordPress Testimonial Slider plugin that allows attackers to bypass access controls. A...

Oct 27, 2025
CVE-2025-62931
8.8

This CVE describes a Missing Authorization vulnerability in the Microsoftstart MSN Partner Hub WordPress plugin that allows attackers to bypass access...

Oct 27, 2025
CVE-2025-62918
8.8

This CVE describes a Missing Authorization vulnerability in the IgnitionDeck WordPress plugin that allows attackers to bypass access controls. Attacke...

Oct 27, 2025
CVE-2025-62889
8.8

This CVE describes a Missing Authorization vulnerability in King Addons for Elementor WordPress plugin that allows attackers to bypass access controls...

Oct 27, 2025
CVE-2025-10706
8.8

The Classified Pro WordPress theme allows authenticated users with subscriber-level access or higher to install arbitrary plugins due to a missing cap...

Oct 16, 2025
CVE-2025-8593
8.8

The GSheetConnector For Gravity Forms WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level...

Oct 11, 2025
CVE-2025-57605
8.8

This vulnerability allows authenticated users in the AiKaan IoT Platform to assign themselves as administrators of other departments, bypassing proper...

Sep 22, 2025
CVE-2025-43358
8.8

A sandbox bypass vulnerability in Apple's macOS and iOS/iPadOS allows shortcuts to escape security restrictions. This affects users running vulnerable...

Sep 15, 2025
CVE-2025-43329
8.8

This CVE describes a sandbox escape vulnerability in Apple's mobile operating systems where an app can bypass its security restrictions. It affects iO...

Sep 15, 2025
CVE-2025-9018
8.8

The Time Tracker WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher ...

Sep 11, 2025
CVE-2025-8425
8.8

The My WP Translate WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher t...

Sep 11, 2025
CVE-2025-55141
8.8

This CVE describes a missing authorization vulnerability in Ivanti security products that allows authenticated users with read-only admin privileges t...

Sep 9, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 2,994 CVEs classified as CWE-862, with 212 rated critical and 816 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free