CVE-2026-13347
templatic1 Hide My WP Lite
The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the HTTP response. Although the output is passed through wp_kses_post(), that function only filters HTML tags and does n...
- CVSS
- 7.5
- EPSS
- 0.60% 45.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10