Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 140/188
4.3
CVE-2024-43296

Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access

4.3
CVE-2024-43297

Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Le

4.3
CVE-2024-43298

Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Le

4.3
CVE-2024-43302

Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Securi

4.3
CVE-2024-43314

Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Config

4.3
CVE-2024-43332

Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control S

4.3
CVE-2024-43343

Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Cons

4.3
CVE-2024-43355

Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Securit

4.3
CVE-2024-43925

Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured

4.3
CVE-2024-43968

Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Secur

4.3
CVE-2024-43973

Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2024-43981

Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectl

4.3
CVE-2024-44006

Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual.Thi

4.3
CVE-2024-44020

Missing Authorization vulnerability in prasadkirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS w

4.3
CVE-2024-44031

Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects J

4.3
CVE-2024-44052

Missing Authorization vulnerability in HelloAsso HelloAsso helloasso.This issue affects HelloAsso: from n/a through <= 1

4.3
CVE-2024-47317

Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded.This issue affects Ads by WP

4.3
CVE-2024-47318

Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n

4.3
CVE-2024-47362

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testim

4.3
CVE-2024-48039

Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Ac

4.3
CVE-2024-48045

Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting

4.3
CVE-2024-7429

The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o

4.3
CVE-2024-10543

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability

4.3
CVE-2024-10588

The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th

4.3
CVE-2024-11125

A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processi

4.3
CVE-2024-10852

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil

4.3
CVE-2024-10853

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c

4.3
CVE-2024-10854

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c

4.3
CVE-2024-10530

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis

4.3
CVE-2024-52549

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc

4.3
CVE-2024-10897

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing c

4.3
CVE-2024-10582

The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modifi

4.3
CVE-2021-3987

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without publi

4.3
CVE-2024-10786

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capabil

4.3
CVE-2024-10533

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check

4.3
CVE-2024-10614

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili

4.3
CVE-2024-48898

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe

4.3
CVE-2024-49680

Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Secur

4.3
CVE-2024-49697

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incor

4.3
CVE-2024-50417

Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Conf

4.3
CVE-2024-51660

Missing Authorization vulnerability in Binsaifullah Easy Accordion Gutenberg Block easy-accordion-block allows Exploitin

4.3
CVE-2024-11154

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner

4.3
CVE-2024-10528

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi

4.3
CVE-2024-10532

The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check

4.3
CVE-2024-11334

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check

4.3
CVE-2024-11354

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of

4.3
CVE-2024-11355

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data

4.3
CVE-2024-10216

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification

4.3
CVE-2024-10537

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of dat

4.3
CVE-2024-9223

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started