Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 41/188
5.3
CVE-2026-9017

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve

5.3
CVE-2026-57774

Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured A

5.3
CVE-2026-57776

Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Co

5.3
CVE-2026-57778

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exp

5.3
CVE-2026-57779

Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Con

5.3
CVE-2026-57781

Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Cont

5.3
CVE-2026-57782

Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Confi

5.3
CVE-2026-61983

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc

5.3
CVE-2026-61985

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl

5.3
CVE-2026-11802

The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versi

5.3
CVE-2026-60118

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated

5.3
CVE-2026-33684

WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded

5.3
CVE-2026-15106

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio

5.3
CVE-2026-8616

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c

5.3
CVE-2026-11868

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio

5.3
CVE-2026-12723

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u

5.3
CVE-2026-65055

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m

5.3
CVE-2026-15827

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check

5.3
CVE-2026-25466

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

5.3
CVE-2026-27355

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

5.3
CVE-2026-27399

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

5.3
CVE-2026-27418

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

5.3
CVE-2026-27422

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

5.3
CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

5.3
CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

5.3
CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

5.3
CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

5.3
CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

5.3
CVE-2026-65472

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

5.3
CVE-2026-65476

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

5.3
CVE-2026-65485

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

5.3
CVE-2026-65486

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

5.3
CVE-2026-65487

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

5.3
CVE-2026-65489

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

5.3
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

5.3
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

5.3
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an

5.3
CVE-2026-12654

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up

5.3
CVE-2026-13390

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega

5.3
CVE-2026-65567

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

5.3
CVE-2026-66477

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

5.3
CVE-2026-12124

The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word

5.3
CVE-2026-13110

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin

5.3
CVE-2026-15411

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for

5.3
CVE-2026-16774

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the

5.3
CVE-2026-13692

The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying

5.3
CVE-2026-4604

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t

5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started