CVE-2022-4681: Hide My WP < 6.2.9 - Unauthenticated SQLi
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4681?
CVE-2022-4681 is a vulnerability in the Hide My WP WordPress plugin before version 6.2.9 that allows for SQL injection.
How severe is CVE-2022-4681?
CVE-2022-4681 has a severity score of 9.8, indicating a critical vulnerability.
Which software versions are affected by CVE-2022-4681?
Versions up to but not including 6.2.9 of the Hide My WP WordPress plugin are affected by CVE-2022-4681.
How does CVE-2022-4681 work?
CVE-2022-4681 allows unauthenticated users to execute SQL injection attacks by not properly sanitizing and escaping a parameter used in a SQL statement via an AJAX action.
How can I fix CVE-2022-4681?
To fix CVE-2022-4681, update the Hide My WP WordPress plugin to version 6.2.9 or later.