CVE-2021-36917: WordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated Plugin Deactivation vulnerability
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36917?
CVE-2021-36917 is considered a critical vulnerability as it allows unauthenticated users to deactivate the WordPress Hide My WP plugin.
How do I fix CVE-2021-36917?
To fix CVE-2021-36917, you should update the Hide My WP plugin to version 6.2.4 or later.
Who is affected by CVE-2021-36917?
Any WordPress site using versions 6.2.3 and earlier of the Hide My WP plugin is affected by CVE-2021-36917.
What are the risks associated with CVE-2021-36917?
The risks include unauthorized deactivation of the security plugin, potentially exposing the site to various attacks.
Is there a way to mitigate CVE-2021-36917 if I cannot update immediately?
Temporary mitigation strategies include disabling the plugin or restricting access to the WordPress admin area until the plugin is updated.