The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat
The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps
The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for
The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which wi
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escala
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t
The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthoriz
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor
The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c
The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, i
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the ne
The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulner
The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. Thi
Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data
The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress
The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check
The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads
The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started