Security Advisory
CVE-2021-36917
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.