nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4681 CVE-2022-4681
CRITICAL
Hide My WP < 6.2.9 - Unauthenticated SQLi
Record summary
CVE-2022-4681 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Hide My WPDefault status: unaffected | CVE List | Before 6.2.9 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBHide My WP < 6.2.9 - Unauthenticated SQLiExploitDB exploitby Xenofon VassilakopoulosNot analyzed1 file
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/5a4096e8-abe4-41c4-b741-c44e740e8689