First published: Mon Feb 06 2023(Updated: )
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Credit: contact@wpscan.com Xenofon Vassilakopoulos
Affected Software | Affected Version | How to fix |
---|---|---|
Hide My WP | <6.2.9 | |
<6.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4681 is a vulnerability in the Hide My WP WordPress plugin before version 6.2.9 that allows for SQL injection.
CVE-2022-4681 has a severity score of 9.8, indicating a critical vulnerability.
Versions up to but not including 6.2.9 of the Hide My WP WordPress plugin are affected by CVE-2022-4681.
CVE-2022-4681 allows unauthenticated users to execute SQL injection attacks by not properly sanitizing and escaping a parameter used in a SQL statement via an AJAX action.
To fix CVE-2022-4681, update the Hide My WP WordPress plugin to version 6.2.9 or later.