Wpwave develops Hide My WP, a WordPress hardening and obfuscation plugin focused on reducing server exposure and concealing site metadata. The recurring vulnerability pattern centers on access-control enforcement and input validation, manifested through SQL injection and authorization-bypass weaknesses in the plugin's administrative and filtering functions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpwave over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4681CRITICAL The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated us | Feb 6, 2023 | 9.8 | 44 | NO | YES |
CVE-2021-36916CRITICAL The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The funct | Nov 24, 2021 | 9.8 | 32 | NO | NO |
CVE-2025-69098HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWave Hide My WP hide_my_wp allows Reflected XSS.This issue affects Hide My W | Jan 22, 2026 | 7.1 | 27 | NO | NO |
CVE-2021-36917HIGH WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the pl | Nov 24, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwave.
Media articles that mention a CVE ID that affects a product developed by Wpwave — matched by CVE ID, not by vendor name.