plugin

Wp Hide Security Enhancer Vulnerabilities

8 known security issues reported for the Wp Hide Security Enhancer WordPress plugin. Most recent disclosed Dec 6, 2024.

2 high 1 medium

Running Wp Hide Security Enhancer on your site? Check whether your installed version is affected.

Scan your site free

WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 2.5.2

unknown

[en] The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to delete the content...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Dec 6, 2024

CVE-2024-11585 on NVD →

WP Hide & Security Enhancer <= 2.5.1 - Missing Authorization to Unauthenticated Arbitrary File Contents Deletion

high

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to delete the contents of...

CVSS:
7.5
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Dec 5, 2024

CVE-2024-11585 on NVD →

WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 1.8

unknown

[en] The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Aug 29, 2022

CVE-2022-2538 on NVD →

WP Hide & Security Enhancer <= 1.7.9.2 - Reflected Cross-Site Scripting

medium

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and 'component' parameters in versions up to, and including, 1.7.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 1.7.9.2
Fixed in:
1.8
Disclosed:
Aug 8, 2022

CVE-2022-2538 on NVD →

WP Hide & Security Enhancer <= 1.3.9.2 - Arbitrary File Download

high

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. This is due to insufficient validation on the file path supplied via the 'file_path' parameter. This makes it possible for attackers to arbitrarily download files such as the wp-config.php file.

CVSS:
7.5
Affected:
up to 1.3.9.2
Fixed in:
1.4
Disclosed:
Jul 21, 2017

WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 1.4.1

unknown

WordPress WP Hide Security Enhancer Plugin below 1.3.9.2 is vulnerable to arbitrary file download. This vulnerability allows an attacker to download any file from the victim web site. Update plugin to v1.4.1

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Jul 21, 2017

WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 1.4

unknown

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. This is due to insufficient validation on the file path supplied via the 'file_path' parameter. This makes it possible for attackers to arbitrarily download files such as the wp-config.php file.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Jul 21, 2017

WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 1.4

unknown

The WP Hide &amp; Security Enhancer WordPress plugin was affected by an Arbitrary File Download security vulnerability.

Affected:
up to 1.4
Fixed in:
1.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database