Lucene search

K

Wpwave Security Vulnerabilities

cve
cve

CVE-2022-4681

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL...

9.8CVSS

9.7AI Score

0.007EPSS

2023-02-06 08:15 PM
44
cve
cve

CVE-2021-36917

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the...

7.5CVSS

7.5AI Score

0.004EPSS

2021-11-24 05:15 PM
18
cve
cve

CVE-2021-36916

The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the...

9.8CVSS

9.6AI Score

0.002EPSS

2021-11-24 05:15 PM
17