CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,077
Total CVEs
231
Critical
877
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
441
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 127
2 Sap 37
3 Apple 27
4 Jenkins 23
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,077)

CVE-2023-33922
4.3

This CVE describes a missing authorization vulnerability in Elementor Website Builder for WordPress. It allows unauthorized users to perform actions t...

Jun 11, 2024
CVE-2023-52217
4.3

This CVE describes a Missing Authorization vulnerability in the weDevs WooCommerce Conversion Tracking WordPress plugin. It allows unauthorized users ...

Jun 11, 2024
CVE-2024-4745
4.3

CVE-2024-4745 is a missing authorization vulnerability in the RafflePress WordPress plugin that allows unauthorized users to access functionality inte...

Jun 10, 2024
CVE-2024-35741
4.3

This CVE describes a Missing Authorization vulnerability in the Awesome Support WordPress plugin that allows unauthorized users to access restricted f...

Jun 10, 2024
CVE-2024-35726
4.3

This CVE describes a Missing Authorization vulnerability in the WooBuddy WordPress plugin that allows unauthorized users to access functionality inten...

Jun 10, 2024
CVE-2024-35722
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Slider Responsive Slideshow plugin that allows unauthorized users to perform...

Jun 10, 2024
CVE-2024-35724
4.3

This CVE describes a Missing Authorization vulnerability in the Bosa Elementor Addons and Templates for WooCommerce WordPress plugin. It allows unauth...

Jun 10, 2024
CVE-2024-22296
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress 12 Step Meeting List plugin that allows unauthorized users to perform action...

Jun 10, 2024
CVE-2024-35720
4.3

This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the Album Gallery WordPress plugin. It allows unauthorized users t...

Jun 10, 2024
CVE-2024-31359
4.3

This CVE describes a Missing Authorization vulnerability in the Premmerce Product Filter for WooCommerce WordPress plugin. It allows unauthorized user...

Jun 9, 2024
CVE-2024-32701
4.3

This CVE describes a missing authorization vulnerability in the InstaWP Connect WordPress plugin. It allows unauthorized users to access functionality...

Jun 9, 2024
CVE-2024-31350
4.3

This CVE describes a Missing Authorization vulnerability in the AWP Classifieds WordPress plugin, allowing unauthorized users to perform actions that ...

Jun 9, 2024
CVE-2024-32804
4.3

This CVE describes a Missing Authorization vulnerability in the WP GoToWebinar WordPress plugin that allows unauthorized users to access functionality...

Jun 9, 2024
CVE-2024-32792
4.3

This CVE describes a Missing Authorization vulnerability in the WPMU DEV Hummingbird WordPress plugin. It allows unauthorized users to access function...

Jun 9, 2024
CVE-2024-32784
4.3

This CVE describes a Missing Authorization vulnerability in the CookieHub WordPress plugin that allows unauthorized users to access functionality inte...

Jun 9, 2024
CVE-2024-35669
4.3

This CVE describes a Missing Authorization vulnerability in the Bowo Debug Log Manager WordPress plugin. It allows unauthorized users to access debug ...

Jun 9, 2024
CVE-2024-34435
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Aiomatic plugin that allows unauthorized users to perform actions intended o...

Jun 9, 2024
CVE-2024-31252
4.3

CVE-2024-31252 is a missing authorization vulnerability in the dFactory Responsive Lightbox WordPress plugin that allows attackers to perform unauthor...

Jun 9, 2024
CVE-2024-31267
4.3

This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WP Desk Flexible Checkout Fields for WooCommerce WordPress plu...

Jun 9, 2024
CVE-2024-30515
4.3

This CVE describes a Missing Authorization vulnerability in the Pixelite Events Manager WordPress plugin. It allows attackers to perform actions witho...

Jun 9, 2024
CVE-2024-31294
4.3

This CVE describes a Missing Authorization vulnerability in the WP Sort Order WordPress plugin that allows unauthorized users to perform actions inten...

Jun 9, 2024
CVE-2024-30537
4.3

This CVE describes a Missing Authorization (Broken Access Control) vulnerability in the WPC Badge Management for WooCommerce WordPress plugin. It allo...

Jun 9, 2024
CVE-2024-4468
4.3

The Salon booking system WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or hi...

Jun 8, 2024
CVE-2024-4661
4.3

The WP Reset WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to modify the ...

Jun 8, 2024
CVE-2024-5489
4.3

The Wbcom Designs Custom Font Uploader WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level acces...

Jun 6, 2024
CVE-2024-4788
4.3

The Boostify Header Footer Builder for Elementor WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-l...

Jun 6, 2024
CVE-2024-35674
4.3

This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows unauthorized users to acc...

Jun 5, 2024
CVE-2024-5453
4.3

The ProfileGrid WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher t...

Jun 5, 2024
CVE-2024-4088
4.3

This vulnerability in the Attire Blocks WordPress plugin allows authenticated users with subscriber-level access or higher to modify plugin settings w...

Jun 5, 2024
CVE-2023-27460
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress CP Contact Form with PayPal plugin. It allows unauthenticated attackers to s...

Jun 3, 2024
CVE-2023-26521
4.3

CVE-2023-26521 is a missing authorization vulnerability in the WordPress Search in Place plugin that allows unauthenticated users to submit feedback t...

Jun 3, 2024
CVE-2024-34803
4.3

This CVE describes a Missing Authorization vulnerability in the Fastly WordPress plugin versions up to 1.2.25. It allows unauthorized users to perform...

Jun 3, 2024
CVE-2024-4427
4.3

The Comparison Slider WordPress plugin has a missing capability check on AJAX actions, allowing authenticated users with subscriber-level access or hi...

May 30, 2024
CVE-2024-1376
4.3

The Event post WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to perform u...

May 24, 2024
CVE-2024-0893
4.3

The Schema App Structured Data plugin for WordPress has a missing capability check that allows authenticated users with subscriber-level access or hig...

May 24, 2024
CVE-2024-3711
4.3

The Brizy Page Builder WordPress plugin has a missing capability check vulnerability that allows authenticated users with contributor-level access or ...

May 23, 2024
CVE-2023-32129
4.3

This CVE describes a Missing Authorization vulnerability in the Sparkle WP Editorialmag WordPress theme. It allows authenticated users with any role t...

May 17, 2024
CVE-2024-4139
4.3

CVE-2024-4139 is a missing authorization vulnerability in SAP's Manage Bank Statement ReProcessing Rules functionality. Authenticated attackers can de...

May 14, 2024
CVE-2024-33956
4.3

This CVE describes a Missing Authorization vulnerability in the Custom WooCommerce Checkout Fields Editor WordPress plugin. It allows unauthorized use...

May 14, 2024
CVE-2024-33573
4.3

This CVE describes a Missing Authorization vulnerability in the EPROLO Dropshipping WordPress plugin that allows unauthorized access to functionality....

May 8, 2024
CVE-2024-4233
4.3

This CVE describes a Missing Authorization vulnerability in three Tyche Softwares WordPress plugins that allows unauthorized users to access functiona...

May 8, 2024
CVE-2024-24833
4.3

This CVE describes a Missing Authorization vulnerability in the Happy Addons for Elementor WordPress plugin. It allows unauthorized users to clone pos...

May 8, 2024
CVE-2024-33570
4.3

This CVE describes a Missing Authorization vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress, allowing unauthorized use...

May 6, 2024
CVE-2024-34389
4.3

This CVE describes a Missing Authorization vulnerability in the WP Post Author WordPress plugin. It allows unauthorized users to perform actions that ...

May 6, 2024
CVE-2024-33925
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Embed Google Fonts plugin. It allows attackers to perform actions without pr...

May 3, 2024
CVE-2024-33914
4.3

This CVE describes a Missing Authorization vulnerability in the Exclusive Addons Elementor WordPress plugin. It allows unauthorized users to duplicate...

May 3, 2024
CVE-2024-24710
4.3

This CVE describes a Missing Authorization vulnerability in the Feed Them Social WordPress plugin that allows unauthorized users to access functionali...

May 3, 2024
CVE-2024-3607
4.3

The PropertyHive WordPress plugin has a missing capability check in the delete_key_date() function, allowing authenticated users with subscriber-level...

May 2, 2024
CVE-2023-1333
4.3

The RapidLoad Power-Up for Autoptimize WordPress plugin has a missing capability check that allows authenticated users with subscriber-level access to...

Mar 10, 2023
CVE-2023-1334
4.3

The RapidLoad Power-Up for Autoptimize WordPress plugin up to version 1.7.1 has a missing capability check on the queue_posts function, allowing authe...

Mar 10, 2023

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,077 CVEs classified as CWE-862, with 231 rated critical and 877 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free