The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve
Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured A
Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Co
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exp
Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Con
Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Confi
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl
The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versi
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying
The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started