Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affect
Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: L
Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Ac
The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder c
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6,
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to un
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthoriz
An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protectio
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of i
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email fo
Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ult
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Fo
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie
The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized m
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unaut
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unaut
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unaut
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized acces
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v
The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing ca
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due
SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perfo
The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authen
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting fro
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing author
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the
The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for W
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started