Hide My WP <= 6.2.12 - Reflected Cross-Site Scripting
medium
The Hide My WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...
- CVSS:
- 6.1
- Affected:
- up to 6.2.12
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2025-69098 on NVD →
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.9
unknown
[en] The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
- Disclosed:
- Feb 6, 2023
CVE-2022-4681 on NVD →
Hide My WP < 6.2.9 - Unauthenticated SQL Injection
critical
The Hide My WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, but not including, 6.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...
- CVSS:
- 9.8
- Affected:
- up to 6.2.9
- Fixed in:
- 6.2.9
- Disclosed:
- Jan 11, 2023
CVE-2022-4681 on NVD →
Hide My WP <= 6.2.3 - Authorization Bypass
high
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
- CVSS:
- 7.5
- Affected:
- up to 6.2.3
- Fixed in:
- 6.2.4
- Disclosed:
- Nov 24, 2021
CVE-2021-36917 on NVD →
Hide My WP <= 6.2.3 - SQL Injection
high
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as...
- CVSS:
- 8.6
- Affected:
- up to 6.2.3
- Fixed in:
- 6.2.4
- Disclosed:
- Nov 24, 2021
CVE-2021-36916 on NVD →
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.4
unknown
[en] The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, su...
- Affected:
- up to 6.2.4
- Fixed in:
- 6.2.4
- Disclosed:
- Nov 24, 2021
CVE-2021-36916 on NVD →
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.4
unknown
[en] WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
- Affected:
- up to 6.2.4
- Fixed in:
- 6.2.4
- Disclosed:
- Nov 24, 2021
CVE-2021-36917 on NVD →
Hide My WP <= 4.53 - Cross-Site Scripting
medium
The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 4.54
- Fixed in:
- 4.54
- Disclosed:
- Aug 13, 2015
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54
unknown
This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML.
Update the plugin.
- Affected:
- up to 4.54
- Fixed in:
- 4.54
- Disclosed:
- Aug 13, 2015
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54
unknown
The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.54
- Fixed in:
- 4.54
- Disclosed:
- Aug 13, 2015
Hide My WP <= 4.51.1 - Cross-Site Scripting
medium
The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.51.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.3
- Affected:
- up to 4.52
- Fixed in:
- 4.52
- Disclosed:
- Jul 28, 2015
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52
unknown
The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.51.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.52
- Fixed in:
- 4.52
- Disclosed:
- Jul 28, 2015
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52
unknown
This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML.
Update the plugin.
- Affected:
- up to 4.52
- Fixed in:
- 4.52
- Disclosed:
- Jul 27, 2015
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54
unknown
An attacker can make a fake attack attempt which will be logged, and can inject JavaScript.
- Affected:
- up to 4.54
- Fixed in:
- 4.54
Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52
unknown
An attacker can make a fake attack attempt, with a JavaScripting payload, which will be logged by the plugin, resulting in XSS. The attacker also can spoof their IP address in the logs by setting the X-FORWARDED-FOR header.
- Affected:
- up to 4.52
- Fixed in:
- 4.52
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database