The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restri
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to
The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch de
The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th
Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attac
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability
The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can cha
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all vers
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p
The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPr
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch
The RevivePress – Keep your Old Content Evergreen plugin for WordPress is vulnerable to unauthorized access and modifica
Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a thro
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Vi
Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0
Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Loca
Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affec
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page G
Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 a
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v
The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.
The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started