The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress
Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS E
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in near
The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi
The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missin
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly
Missing Authorization vulnerability in YMC Filter & Grids allows Accessing Functionality Not Properly Constrained by ACL
Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Confi
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a m
The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un
The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i
The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST
The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any aut
The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4
Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a b
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Pr
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing
Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messag
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t
A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fi
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Se
Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorre
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incor
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and
Missing Authorization vulnerability in Seerox Easy Blocks pro easy-blocks-pro allows Accessing Functionality Not Properl
Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Men
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission
An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started