Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 93/188
4.3
CVE-2024-13424

The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab

4.3
CVE-2024-13717

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data du

4.3
CVE-2024-13530

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login

4.3
CVE-2024-13651

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of dat

4.3
CVE-2024-50500

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploi

4.3
CVE-2025-22260

Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Ta

4.3
CVE-2025-22681

Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly

4.3
CVE-2025-22694

Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerc

4.3
CVE-2024-11134

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '

4.3
CVE-2025-22643

Missing Authorization vulnerability in famethemes OnePress onepress allows Exploiting Incorrectly Configured Access Cont

4.3
CVE-2024-1539

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10

4.3
CVE-2025-1074

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout

4.3
CVE-2025-1084

A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by

4.3
CVE-2025-25120

Missing Authorization vulnerability in Melodic Media Slide Banners slide-banners allows Exploiting Incorrectly Configure

4.3
CVE-2025-23189

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker cou

4.3
CVE-2025-23190

Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows t

4.3
CVE-2024-13541

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due

4.3
CVE-2024-12164

The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized

4.3
CVE-2024-13374

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thew

4.3
CVE-2025-26367

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2

4.3
CVE-2024-13229

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of dat

4.3
CVE-2024-13639

The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss

4.3
CVE-2025-0935

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing cap

4.3
CVE-2024-13439

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab

4.3
CVE-2025-1358

A vulnerability classified as problematic was found in Pix Software Vivaz 6.0.10. This vulnerability affects unknown cod

4.3
CVE-2025-26773

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Cont

4.3
CVE-2024-13687

The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missin

4.3
CVE-2024-13783

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for

4.3
CVE-2025-1557

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The man

4.3
CVE-2025-1643

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some un

4.3
CVE-2025-1644

A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown functi

4.3
CVE-2025-26871

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Inc

4.3
CVE-2025-26928

Missing Authorization vulnerability in Xfinitysoft Order Limit for WooCommerce wc-order-limit-lite allows Exploiting Inc

4.3
CVE-2025-26948

Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a

4.3
CVE-2025-26983

Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom

4.3
CVE-2025-1091

A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if t

4.3
CVE-2025-1745

A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unkno

4.3
CVE-2024-13716

The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit

4.3
CVE-2024-10860

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data

4.3
CVE-2024-13358

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to

4.3
CVE-2025-1780

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to

4.3
CVE-2025-1813

A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unk

4.3
CVE-2025-1891

A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. T

4.3
CVE-2024-13686

The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability che

4.3
CVE-2024-13747

The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a miss

4.3
CVE-2024-13810

The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access

4.3
CVE-2024-13811

The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthoriz

4.3
CVE-2025-1666

The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorize

4.3
CVE-2025-2042

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects

4.3
CVE-2024-13526

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started