CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,077)
This CVE describes a missing authorization vulnerability in Elementor Website Builder for WordPress. It allows unauthorized users to perform actions t...
Jun 11, 2024This CVE describes a Missing Authorization vulnerability in the weDevs WooCommerce Conversion Tracking WordPress plugin. It allows unauthorized users ...
Jun 11, 2024CVE-2024-4745 is a missing authorization vulnerability in the RafflePress WordPress plugin that allows unauthorized users to access functionality inte...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the WooBuddy WordPress plugin that allows unauthorized users to access functionality inten...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Slider Responsive Slideshow plugin that allows unauthorized users to perform...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the Bosa Elementor Addons and Templates for WooCommerce WordPress plugin. It allows unauth...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the WordPress 12 Step Meeting List plugin that allows unauthorized users to perform action...
Jun 10, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the Album Gallery WordPress plugin. It allows unauthorized users t...
Jun 10, 2024This CVE describes a Missing Authorization vulnerability in the Premmerce Product Filter for WooCommerce WordPress plugin. It allows unauthorized user...
Jun 9, 2024This CVE describes a missing authorization vulnerability in the InstaWP Connect WordPress plugin. It allows unauthorized users to access functionality...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the AWP Classifieds WordPress plugin, allowing unauthorized users to perform actions that ...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WP GoToWebinar WordPress plugin that allows unauthorized users to access functionality...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WPMU DEV Hummingbird WordPress plugin. It allows unauthorized users to access function...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the CookieHub WordPress plugin that allows unauthorized users to access functionality inte...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Bowo Debug Log Manager WordPress plugin. It allows unauthorized users to access debug ...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Aiomatic plugin that allows unauthorized users to perform actions intended o...
Jun 9, 2024CVE-2024-31252 is a missing authorization vulnerability in the dFactory Responsive Lightbox WordPress plugin that allows attackers to perform unauthor...
Jun 9, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WP Desk Flexible Checkout Fields for WooCommerce WordPress plu...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the Pixelite Events Manager WordPress plugin. It allows attackers to perform actions witho...
Jun 9, 2024This CVE describes a Missing Authorization vulnerability in the WP Sort Order WordPress plugin that allows unauthorized users to perform actions inten...
Jun 9, 2024This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WPC Badge Management for WooCommerce WordPress plugin. It allo...
Jun 9, 2024The Salon booking system WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or hi...
Jun 8, 2024The WP Reset WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to modify the ...
Jun 8, 2024The Wbcom Designs Custom Font Uploader WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level acces...
Jun 6, 2024The Boostify Header Footer Builder for Elementor WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-l...
Jun 6, 2024This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows unauthorized users to acc...
Jun 5, 2024The ProfileGrid WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher t...
Jun 5, 2024This vulnerability in the Attire Blocks WordPress plugin allows authenticated users with subscriber-level access or higher to modify plugin settings w...
Jun 5, 2024This CVE describes a Missing Authorization vulnerability in the WordPress CP Contact Form with PayPal plugin. It allows unauthenticated attackers to s...
Jun 3, 2024CVE-2023-26521 is a missing authorization vulnerability in the WordPress Search in Place plugin that allows unauthenticated users to submit feedback t...
Jun 3, 2024This CVE describes a Missing Authorization vulnerability in the Fastly WordPress plugin versions up to 1.2.25. It allows unauthorized users to perform...
Jun 3, 2024The Comparison Slider WordPress plugin has a missing capability check on AJAX actions, allowing authenticated users with subscriber-level access or hi...
May 30, 2024The Event post WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to perform u...
May 24, 2024The Schema App Structured Data plugin for WordPress has a missing capability check that allows authenticated users with subscriber-level access or hig...
May 24, 2024The Brizy Page Builder WordPress plugin has a missing capability check vulnerability that allows authenticated users with contributor-level access or ...
May 23, 2024This CVE describes a Missing Authorization vulnerability in the Sparkle WP Editorialmag WordPress theme. It allows authenticated users with any role t...
May 17, 2024CVE-2024-4139 is a missing authorization vulnerability in SAP's Manage Bank Statement ReProcessing Rules functionality. Authenticated attackers can de...
May 14, 2024This CVE describes a Missing Authorization vulnerability in the Custom WooCommerce Checkout Fields Editor WordPress plugin. It allows unauthorized use...
May 14, 2024This CVE describes a Missing Authorization vulnerability in the EPROLO Dropshipping WordPress plugin that allows unauthorized access to functionality....
May 8, 2024This CVE describes a Missing Authorization vulnerability in three Tyche Softwares WordPress plugins that allows unauthorized users to access functiona...
May 8, 2024This CVE describes a Missing Authorization vulnerability in the Happy Addons for Elementor WordPress plugin. It allows unauthorized users to clone pos...
May 8, 2024This CVE describes a Missing Authorization vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress, allowing unauthorized use...
May 6, 2024This CVE describes a Missing Authorization vulnerability in the WP Post Author WordPress plugin. It allows unauthorized users to perform actions that ...
May 6, 2024This CVE describes a Missing Authorization vulnerability in the WordPress Embed Google Fonts plugin. It allows attackers to perform actions without pr...
May 3, 2024This CVE describes a Missing Authorization vulnerability in the Exclusive Addons Elementor WordPress plugin. It allows unauthorized users to duplicate...
May 3, 2024This CVE describes a Missing Authorization vulnerability in the Feed Them Social WordPress plugin that allows unauthorized users to access functionali...
May 3, 2024The PropertyHive WordPress plugin has a missing capability check in the delete_key_date() function, allowing authenticated users with subscriber-level...
May 2, 2024The RapidLoad Power-Up for Autoptimize WordPress plugin has a missing capability check that allows authenticated users with subscriber-level access to...
Mar 10, 2023The RapidLoad Power-Up for Autoptimize WordPress plugin up to version 1.7.1 has a missing capability check on the queue_posts function, allowing authe...
Mar 10, 2023About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,077 CVEs classified as CWE-862, with 231 rated critical and 877 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free