WP Hide <= 0.0.2 - Missing Authorization to Settings Update
highThe WP Hide plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when updating the custom_wpadmin_slug setting in versions up to, and including, 0.0.2. This makes it possible for unauthenticated attackers to change the plugin's settings, which consists of the administrative login...
- CVSS:
- 7.5
- Affected:
- up to 0.0.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 17, 2022