What the vulnerability does
01Description
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
Explanation of Vulnerability in Simple Terms
Hide My WP versions up to 6.2.3 contain an access control flaw that allows unauthenticated attackers to modify site data over the network without user interaction. The plugin fails to properly restrict access to sensitive functions, enabling attackers to alter content or settings. Site administrators should update immediately to a version newer than 6.2.3.
What an attacker can do
Modify site data or settings without logging in.
Potential impact on your site
Attackers can alter your site's content, settings, or functionality without your knowledge or permission.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities