CVE-2021-36917
MEDIUMHide My WP < 6.2.3 - Unauthenticated Plugin Deactivation via Reset Token
Title source: llmDescription
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
References (3)
Core 3
Core References
Product x_refsource_confirm
https://codecanyon.net/item/hide-my-wp-amazing-security-plugin-for-wordpress/4177158
Exploit, Third Party Advisory x_refsource_misc
https://patchstack.com/hide-my-wp-vulnerabilities-fixed/
Third Party Advisory x_refsource_misc
https://patchstack.com/database/vulnerability/hide-my-wp/wordpress-hide-my-wp-premium-plugin-6-2-3-unauthenticated-plugin-deactivation-vulnerability
Scores
CVSS v3
6.5
EPSS
0.0194
EPSS Percentile
77.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
CWE-862
Status
published
Products (2)
wpWave/Hide My WP (WordPress plugin)
<= 6.2.3 - 6.2.3
wpwave/hide_my_wp
< 6.2.3
Published
Nov 24, 2021
Tracked Since
Feb 18, 2026