plugin

Hide My Wp Vulnerabilities

15 known security issues reported for the Hide My Wp WordPress plugin. Most recent disclosed Jan 13, 2026.

1 critical 2 high 3 medium

Running Hide My Wp on your site? Check whether your installed version is affected.

Scan your site free

Hide My WP <= 6.2.12 - Reflected Cross-Site Scripting

medium

The Hide My WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 6.2.12
Fix:
No patched version reported
Disclosed:
Jan 13, 2026

CVE-2025-69098 on NVD →

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.9

unknown

[en] The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Feb 6, 2023

CVE-2022-4681 on NVD →

Hide My WP < 6.2.9 - Unauthenticated SQL Injection

critical

The Hide My WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, but not including, 6.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...

CVSS:
9.8
Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Jan 11, 2023

CVE-2022-4681 on NVD →

Hide My WP <= 6.2.3 - Authorization Bypass

high

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

CVSS:
7.5
Affected:
up to 6.2.3
Fixed in:
6.2.4
Disclosed:
Nov 24, 2021

CVE-2021-36917 on NVD →

Hide My WP <= 6.2.3 - SQL Injection

high

The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as...

CVSS:
8.6
Affected:
up to 6.2.3
Fixed in:
6.2.4
Disclosed:
Nov 24, 2021

CVE-2021-36916 on NVD →

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.4

unknown

[en] The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, su...

Affected:
up to 6.2.4
Fixed in:
6.2.4
Disclosed:
Nov 24, 2021

CVE-2021-36916 on NVD →

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 6.2.4

unknown

[en] WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

Affected:
up to 6.2.4
Fixed in:
6.2.4
Disclosed:
Nov 24, 2021

CVE-2021-36917 on NVD →

Hide My WP <= 4.53 - Cross-Site Scripting

medium

The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 4.54
Fixed in:
4.54
Disclosed:
Aug 13, 2015

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54

unknown

This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML. Update the plugin.

Affected:
up to 4.54
Fixed in:
4.54
Disclosed:
Aug 13, 2015

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54

unknown

The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.54
Fixed in:
4.54
Disclosed:
Aug 13, 2015

Hide My WP <= 4.51.1 - Cross-Site Scripting

medium

The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.51.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.3
Affected:
up to 4.52
Fixed in:
4.52
Disclosed:
Jul 28, 2015

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52

unknown

The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.51.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.52
Fixed in:
4.52
Disclosed:
Jul 28, 2015

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52

unknown

This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML. Update the plugin.

Affected:
up to 4.52
Fixed in:
4.52
Disclosed:
Jul 27, 2015

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.54

unknown

An attacker can make a fake attack attempt which will be logged, and can inject JavaScript.

Affected:
up to 4.54
Fixed in:
4.54

Hide My WP - Amazing Security Plugin for WordPress! [hide_my_wp] < 4.52

unknown

An attacker can make a fake attack attempt, with a JavaScripting payload, which will be logged by the plugin, resulting in XSS. The attacker also can spoof their IP address in the logs by setting the X-FORWARDED-FOR header.

Affected:
up to 4.52
Fixed in:
4.52

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database