vendor:
Hide My WP
by:
Xenofon Vassilakopoulos
8.1
CVSS
CRITICAL
Unauthenticated SQL Injection
89
CWE
Product Name: Hide My WP
Affected Version From: 6.2.2008
Affected Version To: 6.2.2008
Patch Exists: YES
Related CWE: CVE-2022-4681
CPE: a:wpwave:hide_my_wp:6.2.8
Platforms Tested:
2023
WordPress Plugin Hide My WP < 6.2.9 - Unauthenticated SQLi
The Hide My WP Wordpress plugin before version 6.2.9 does not properly sanitize user input, allowing unauthenticated users to perform SQL injection attacks via AJAX actions.
Mitigation:
Update to version 6.2.9 or later to patch this vulnerability. Avoid using plugins with known security issues.