The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX ac
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX ac
The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated a
The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of da
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th
The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil
The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unaut
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of d
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a
The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio
The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the documen
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an impr
The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres
The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce pl
The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil
The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data d
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of da
The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of d
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attack
The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit
The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates
The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil
The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Gener
The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce:
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started