Description
Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.
Published: 2025-12-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that allows an attacker to bypass the default access control checks in the WordPress Hide Plugins plugin. Because the plugin does not enforce proper permission checks, an attacker can read or modify plugin configuration and potentially access or reveal sensitive data about which plugins are hidden. The weakness is classified as CWE‑862, indicating that reference control checks are inadequate. The primary impact is that the attacker can gain unauthorized access to plugin management functionality, which may influence the visibility of installed plugins and affect the integrity of the site’s plugin inventory.

Affected Systems

The affected product is the ThemeBoy Hide Plugins plugin for WordPress, versions from the initial release up through version 1.0.4. Any WordPress installation that has a copy of this plugin in any of these versions is considered vulnerable. The plugin does not place version constraints on WordPress itself, so the vulnerability is present regardless of the WordPress core version, as long as the plugin is installed.

Risk and Exploitability

The CVSS score for this issue is 4.3, indicating a moderate severity. The EPSS score of less than 1% reflects a low probability that the flaw is being actively exploited, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, through the web interface, where an authenticated user with insufficient privileges can manipulate or view plugin settings without back‑end permission verification. Because the flaw involves a failure of access control, an attacker with at least a low‑tier role could gain excessive permission, but no prerequisite network access or privileged credentials are specified. Overall, the risk is moderate and the exploitation likelihood is low; however, organizations should still remediate promptly to prevent potential elevation of privileges or accidental disclosure of hidden plugin information.

Generated by OpenCVE AI on April 29, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Hide Plugins to a version newer than 1.0.4 when it becomes available
  • If an update is not possible, remove or disable the Hide Plugins plugin so that its files are no longer accessible
  • Ensure that WordPress role‑based access control is configured correctly so that only administrators can edit plugin settings
  • Review WordPress security settings and monitoring for anomalous plugin file accesses

Generated by OpenCVE AI on April 29, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeBoy Hide Plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through 1.0.4. Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeBoy Hide Plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through 1.0.4.
Title WordPress Hide Plugins plugin <= 1.0.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:01.810Z

Reserved: 2025-10-07T15:41:34.896Z

Link: CVE-2025-62115

cve-icon Vulnrichment

Updated: 2025-12-31T17:33:10.193Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T17:15:46.323

Modified: 2026-04-23T15:34:34.187

Link: CVE-2025-62115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:00:13Z

Weaknesses