The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.Thi
Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affe
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modi
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing me
Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.
An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious websit
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C
Windows Text Services Framework Elevation of Privilege Vulnerability
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable t
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T
Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by AC
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized
Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting Incorrectly Configured Access Con
Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Cont
The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit
The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab
The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file
The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized m
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE
The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead
The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil
An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local ar
The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal
Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk
Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue
Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra
The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora
The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary
Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started