CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (2,994)
This CVE describes a Missing Authorization vulnerability in the Userpro WordPress plugin by DeluxeThemes. It allows attackers to bypass access control...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the Bit Assist WordPress plugin that allows attackers to bypass access controls. It affect...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls. It affec...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls and perfo...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the Trustindex Widgets for Social Photo Feed WordPress plugin. It allows attackers to expl...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the Funnelforms Free WordPress plugin that allows attackers to bypass access controls. Att...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the WP Document Revisions WordPress plugin that allows attackers to bypass access controls...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the Cooked WordPress plugin that allows attackers to bypass access controls. It affects al...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the SALESmanago WordPress plugin that allows attackers to bypass access controls. It affec...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the Spider Themes BBP Core WordPress plugin that allows attackers to bypass access control...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the Wappointment WordPress plugin that allows attackers to bypass access controls. It affe...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the Virusdie WordPress plugin that allows attackers to bypass access controls. Attackers c...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the WP Time Slots Booking Form WordPress plugin that allows attackers to bypass access con...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the WpStream WordPress plugin that allows attackers to bypass access controls and perform ...
Dec 24, 2025This CVE describes a Missing Authorization vulnerability in the WpStream WordPress plugin that allows attackers to bypass access controls and perform ...
Dec 24, 2025This CVE describes a missing authorization vulnerability in the icc0rz H5P WordPress plugin that allows attackers to bypass access controls. It affect...
Dec 24, 2025The Demo Importer Plus WordPress plugin has a critical vulnerability that allows authenticated attackers with Subscriber-level access or higher to tri...
Dec 18, 2025The Postem Ipsum WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher to c...
Dec 13, 2025CVE-2021-47701 is a privilege escalation vulnerability in OpenBMCS 2.4 that allows authenticated users with read-only permissions to elevate their pri...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the Webba Booking WordPress plugin that allows attackers to bypass access controls. Attack...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in Mikado-Themes Powerlift WordPress theme that allows attackers to bypass access controls. I...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Elated-Themes The Aisle WordPress theme that allows attackers to bypass access control...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WordPress Photo Block plugin that allows attackers to bypass access controls. Attacker...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the Virtuaria PagBank/PagSeguro para Woocommerce WordPress plugin that allows attackers to...
Dec 9, 2025This CVE describes a Missing Authorization vulnerability in the ConveyThis WordPress translation plugin that allows attackers to bypass access control...
Dec 9, 2025This CVE describes a missing authorization vulnerability in the WordPress Quick Interest Slider plugin that allows attackers to bypass access controls...
Dec 9, 2025The Realty Portal WordPress plugin versions 0.1 to 0.4.1 contain a missing capability check vulnerability that allows authenticated users with Subscri...
Nov 21, 2025This CVE describes a Missing Authorization vulnerability in the VikBooking Hotel Booking Engine & PMS WordPress plugin. It allows attackers to bypass ...
Nov 6, 2025This CVE describes a missing authorization vulnerability in the WordPress Backup and Move plugin that allows attackers to bypass access controls. Atta...
Nov 6, 2025This CVE describes a Missing Authorization vulnerability in the bPlugins Image Gallery WordPress plugin (versions up to 1.0.7). It allows attackers to...
Nov 6, 2025This vulnerability allows authenticated WordPress users with subscriber-level access or higher to install arbitrary plugin packages from crafted URLs,...
Nov 4, 2025CVE-2025-64349 is an access control vulnerability in ELOG that allows authenticated users to modify other users' profiles. An attacker can change a ta...
Oct 31, 2025Nagios XI versions before 2024R1 have a missing access control vulnerability in the Web SSH Terminal. Remote attackers with low privileges can access ...
Oct 30, 2025This CVE describes a Missing Authorization vulnerability in the MDZ Persian Admin Fonts WordPress plugin that allows attackers to bypass access contro...
Oct 27, 2025This CVE describes a missing authorization vulnerability in the QuantumCloud ChatBot WordPress plugin that allows attackers to bypass access controls....
Oct 27, 2025This CVE describes a missing authorization vulnerability in the Revive Old Posts WordPress plugin (also known as tweet-old-post) that allows attackers...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in the Everest Backup WordPress plugin that allows attackers to bypass access controls and po...
Oct 27, 2025This vulnerability allows attackers to bypass authorization controls in the Post Grid and Gutenberg Blocks WordPress plugin, potentially accessing or ...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Testimonial Slider plugin that allows attackers to bypass access controls. A...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in the Microsoftstart MSN Partner Hub WordPress plugin that allows attackers to bypass access...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in the IgnitionDeck WordPress plugin that allows attackers to bypass access controls. Attacke...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in King Addons for Elementor WordPress plugin that allows attackers to bypass access controls...
Oct 27, 2025The Classified Pro WordPress theme allows authenticated users with subscriber-level access or higher to install arbitrary plugins due to a missing cap...
Oct 16, 2025The GSheetConnector For Gravity Forms WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level...
Oct 11, 2025This vulnerability allows authenticated users in the AiKaan IoT Platform to assign themselves as administrators of other departments, bypassing proper...
Sep 22, 2025A sandbox bypass vulnerability in Apple's macOS and iOS/iPadOS allows shortcuts to escape security restrictions. This affects users running vulnerable...
Sep 15, 2025This CVE describes a sandbox escape vulnerability in Apple's mobile operating systems where an app can bypass its security restrictions. It affects iO...
Sep 15, 2025The Time Tracker WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher ...
Sep 11, 2025The My WP Translate WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher t...
Sep 11, 2025This CVE describes a missing authorization vulnerability in Ivanti security products that allows authenticated users with read-only admin privileges t...
Sep 9, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 2,994 CVEs classified as CWE-862, with 212 rated critical and 816 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free