CVE-2021-36917 MEDIUM

CVE-2021-36917: WordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated Plugin Deactivation vulnerability

Vendor Wpwave
Product Hide My WP (WordPress plugin)
Weakness CWE-284
Published November 24, 2021
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

Explanation of Vulnerability in Simple Terms

02Summary

Hide My WP versions up to 6.2.3 contain an access control flaw that allows unauthenticated attackers to modify site data over the network without user interaction. The plugin fails to properly restrict access to sensitive functions, enabling attackers to alter content or settings. Site administrators should update immediately to a version newer than 6.2.3.

What an attacker can do

03Attacker Capabilities

Modify site data or settings without logging in.

Potential impact on your site

04Site Impact

Attackers can alter your site's content, settings, or functionality without your knowledge or permission.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

November 24, 2021 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE