PT-2023-15053 · WordPress · Hide My Wp

Xenofon Vassilakopoulos

·

Published

2023-02-06

·

Updated

2025-03-25

·

CVE-2022-4681

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hide My WP WordPress plugin versions prior to 6.2.9
Description The issue arises from the plugin's failure to properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action. This AJAX action is available to unauthenticated users, leading to a SQL injection.
Recommendations For versions prior to 6.2.9, update to version 6.2.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-4681

Affected Products

Hide My Wp