Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-44232
Disclosure Date: October 09, 2023 (last updated October 12, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Hide Pages plugin <= 1.0 versions.
0
Attacker Value
Unknown
CVE-2022-4537
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.
0
Attacker Value
Unknown
CVE-2022-4681
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
0
Attacker Value
Unknown
CVE-2022-3489
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
0
Attacker Value
Unknown
CVE-2022-2538
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-36917
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
0
Attacker Value
Unknown
CVE-2021-36916
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible.
0