vendor:
                    Hide My WP
                by:
                    Xenofon Vassilakopoulos
                8.1
                        CVSS
                    CRITICAL
                    Unauthenticated SQL Injection
                    89
                        CWE
                    Product Name: Hide My WP
                    Affected Version From:  6.2.2008
                    Affected Version To:  6.2.2008
                    Patch Exists: YES
                    Related CWE: CVE-2022-4681
                    CPE:  a:wpwave:hide_my_wp:6.2.8
                    Platforms Tested:  
                    2023
                    WordPress Plugin Hide My WP < 6.2.9 - Unauthenticated SQLi
The Hide My WP Wordpress plugin before version 6.2.9 does not properly sanitize user input, allowing unauthenticated users to perform SQL injection attacks via AJAX actions.
Mitigation:
					Update to version 6.2.9 or later to patch this vulnerability. Avoid using plugins with known security issues.