CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,077)
The SendGrid for WordPress plugin has a missing capability check that allows authenticated users with Subscriber-level access or higher to delete the ...
Oct 18, 2024This vulnerability in the Paytium WordPress plugin allows authenticated attackers with subscriber-level access to verify the existence of a Mollie pay...
Oct 16, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to deactivate the Multiline files upload for contact fo...
Oct 16, 2024The Order Attachments for WooCommerce WordPress plugin versions 2.0 to 2.4.1 has a missing capability check on the wcoa_add_attachment AJAX action, al...
Oct 12, 2024The ImagePress – Image Gallery WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or h...
Oct 12, 2024The Notification for Telegram WordPress plugin versions up to 3.3.1 contain an authorization bypass vulnerability that allows authenticated users with...
Oct 10, 2024The Soumettre.fr WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher to di...
Oct 1, 2024The Download Monitor WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to ena...
Sep 26, 2024The Easy Mega Menu Plugin for WordPress has a missing capability check on AJAX functions, allowing authenticated users with subscriber-level access or...
Sep 25, 2024This vulnerability in the HTML5 Video Player WordPress plugin allows authenticated attackers with Subscriber-level access or higher to modify plugin s...
Sep 11, 2024This vulnerability in SAP for Oil & Gas (Transportation and Distribution) allows authenticated non-administrative users to delete non-sensitive entrie...
Sep 10, 2024This vulnerability in SAP's RFC-enabled function module allows low-privileged users to add URLs to any user's workplace favorites. This enables attack...
Sep 10, 2024This vulnerability in SAP's RFC-enabled function module allows low-privileged users to read any user's workplace favorites and user menu data, includi...
Sep 10, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify plugin settings and forms without proper auth...
Sep 6, 2024This vulnerability in OpenStack Ironic and ironic-python-agent allows authenticated users to craft malicious images that could trigger unexpected beha...
Sep 6, 2024The HelloAsso WordPress plugin has an authorization vulnerability where authenticated users with Contributor-level access or higher can modify plugin ...
Sep 5, 2024The Geo Controller WordPress plugin has insufficient access controls that allow authenticated users with Subscriber-level permissions or higher to cre...
Sep 5, 2024CVE-2024-39591 is an authorization bypass vulnerability in SAP Document Builder where a specific function module lacks proper authorization checks. Th...
Aug 13, 2024This vulnerability in SAP Student Life Cycle Management (SLcM) allows authenticated users to bypass authorization checks and delete non-sensitive repo...
Aug 13, 2024The Orchid Store WordPress theme has a missing capability check that allows authenticated users with Subscriber-level access or higher to activate the...
Aug 8, 2024This vulnerability in the WordPress Sync Post With Other Site plugin allows authenticated attackers with Subscriber-level access or higher to create d...
Aug 3, 2024This vulnerability in XWiki Platform allows users with view-only permissions on a page to delete and replace it with new content, bypassing edit and d...
Jul 31, 2024The Tutor LMS Migration Tool WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access o...
Jul 27, 2024This vulnerability allows authenticated WordPress users with Contributor-level access or higher to modify plugin settings without proper authorization...
Jul 24, 2024The YITH Essential Kit for WooCommerce #1 WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscribe...
Jul 19, 2024The Duplica WordPress plugin has a missing capability check vulnerability that allows authenticated attackers with Subscriber-level access or higher t...
Jul 18, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to perform unauthorized API operations in the Email Sub...
Jul 17, 2024This vulnerability in the Eventin WordPress plugin allows authenticated attackers with Contributor-level access or higher to import unauthorized data ...
Jul 17, 2024CVE-2024-39596 is a missing authorization vulnerability in SAP Enable Now that allows authenticated authors to escalate privileges and access restrict...
Jul 9, 2024CVE-2024-37175 is a missing authorization vulnerability in SAP CRM WebClient that allows authenticated users to escalate privileges and access sensiti...
Jul 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress EmbedPress plugin that allows unauthorized users to perform actions they sho...
Jun 21, 2024The Hide Dashboard Notifications WordPress plugin has a missing capability check vulnerability that allows authenticated users with contributor-level ...
Jun 21, 2024This CVE describes a Missing Authorization vulnerability in the Wpmet Elements Kit Elementor addons plugin for WordPress. It allows unauthorized users...
Jun 19, 2024This CVE describes a missing authorization vulnerability in the Avada WordPress theme that allows authenticated users to perform actions they shouldn'...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in Automattic's Jetpack WordPress plugin that allows contributors to perform actions they sho...
Jun 19, 2024This vulnerability allows guest users in JetBrains YouTrack to attach files to articles, which should be restricted. It affects YouTrack instances wit...
Jun 18, 2024CVE-2023-51376 is a missing authorization vulnerability in the ProjectHuddle Client Site WordPress plugin that allows unauthorized users to access fun...
Jun 14, 2024CVE-2023-35045 is a missing authorization vulnerability in the Fat Rat Collect WordPress plugin that allows unauthorized users to access functionality...
Jun 14, 2024CVE-2023-51524 is a missing authorization vulnerability in the weForms WordPress plugin that allows unauthorized users to access form submission data ...
Jun 12, 2024CVE-2023-47828 is a missing authorization vulnerability in the wpMandrill WordPress plugin that allows unauthorized users to access certain administra...
Jun 12, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the ProfileGrid WordPress plugin. It allows unauthorized users to ...
Jun 12, 2024This CVE describes a Missing Authorization vulnerability in the FunnelKit Checkout WordPress plugin that allows authenticated users to activate arbitr...
Jun 12, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Simple Staff List plugin that allows unauthorized users to access restricted...
Jun 12, 2024This CVE describes a Missing Authorization vulnerability in the Aspose.Words Exporter WordPress plugin that allows unauthorized users to access functi...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Revolut Gateway for WooCommerce WordPress plugin. It allows unauthorized users to acce...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the ACF Photo Gallery Field WordPress plugin. It allows unauthorized users to access or mo...
Jun 11, 2024This CVE describes a missing authorization vulnerability in the Soliloquy Slider WordPress plugin that allows unauthorized users to access functionali...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the WP Discourse WordPress plugin that allows unauthorized users to perform actions intend...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the Photo Gallery by 10Web WordPress plugin. It allows unauthorized users to perform actio...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the SportsPress WordPress plugin that allows unauthorized users to perform actions they sh...
Jun 11, 2024About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,077 CVEs classified as CWE-862, with 231 rated critical and 877 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free