7.5

CVE-2021-36917

Exploit

WordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated Plugin Deactivation vulnerability

Hide My WP <= 6.2.3 - Authorization Bypass

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
Mögliche Gegenmaßnahme
Hide My WP - Amazing Security Plugin for WordPress!: Update to version 6.2.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpwaveHide My Wp SwPlatformwordpress Version <= 6.2.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Hide My WP - Amazing Security Plugin for WordPress!
Version *-6.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.94% 0.775
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
audit@patchstack.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://codecanyon.net/item/hide-my-wp-amazing-security-plugin-for-wordpress/4177158
Product
https://patchstack.com/hide-my-wp-vulnerabilities-fixed/
Third Party Advisory
Exploit
https://patchstack.com/database/vulnerability/hide-my-wp/wordpress-hide-my-wp-premium-plugin-6-2-3-unauthenticated-plugin-deactivation-vulnerability
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/3283f2b7-28a5-4c39-aeef-3237ecc57cf3
Third Party Advisory