The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati
Missing Authorization vulnerability in EazyPlugins Eazy Plugin Manager plugins-on-steroids allows Exploiting Incorrectly
Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Pri
Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue
Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows P
The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg
The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to
The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the new
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services witho
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insuff
Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allow
The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the p
The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This is
Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue
Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attac
SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control
Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured
The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi
The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authentic
The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within
The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks
The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability
The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all v
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to esca
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e
The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7,
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the s
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than,
The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du
The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che
Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, lo
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address,
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz
Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of
The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started