Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin WP Hide and SEO Hooks Allows Arbitrary File Uploads

MINI-whc8-crc9-hcjp
Summary

A WordPress plugin that helps with search engine optimization allows attackers to upload any file to a website. This can be used to install malware or steal sensitive data. Update the plugin to the latest version to fix this issue.

What to do
  • Update opensearch-3 to version 3.6.0-r0.
  • Update opensearch-3-oci-entrypoint to version 3.6.0-r0.
  • Update opensearch-3-analysis-icu to version 3.6.0-r0.
  • Update opensearch-3-analysis-kuromoji to version 3.6.0-r0.
  • Update opensearch-3-analysis-nori to version 3.6.0-r0.
  • Update opensearch-3-analysis-phonetic to version 3.6.0-r0.
  • Update opensearch-3-analysis-smartcn to version 3.6.0-r0.
  • Update opensearch-3-analysis-stempel to version 3.6.0-r0.
  • Update opensearch-3-analysis-ukrainian to version 3.6.0-r0.
  • Update opensearch-3-crypto-kms to version 3.6.0-r0.
  • Update opensearch-3-discovery-azure-classic to version 3.6.0-r0.
  • Update opensearch-3-discovery-ec2 to version 3.6.0-r0.
  • Update opensearch-3-discovery-gce to version 3.6.0-r0.
  • Update opensearch-3-ingest-attachment to version 3.6.0-r0.
  • Update opensearch-3-mapper-annotated-text to version 3.6.0-r0.
  • Update opensearch-3-mapper-murmur3 to version 3.6.0-r0.
  • Update opensearch-3-mapper-size to version 3.6.0-r0.
  • Update opensearch-3-repository-azure to version 3.6.0-r0.
  • Update opensearch-3-repository-gcs to version 3.6.0-r0.
  • Update opensearch-3-repository-s3 to version 3.6.0-r0.
  • Update opensearch-3-store-smb to version 3.6.0-r0.
  • Update opensearch-3-telemetry-otel to version 3.6.0-r0.
  • Update opensearch-3-alerting to version 3.6.0-r0.
  • Update opensearch-3-anomaly-detection to version 3.6.0-r0.
  • Update opensearch-3-asynchronous-search to version 3.6.0-r0.
  • Update opensearch-3-cross-cluster-replication to version 3.6.0-r0.
  • Update opensearch-3-custom-codecs to version 3.6.0-r0.
  • Update opensearch-3-flow-framework to version 3.6.0-r0.
  • Update opensearch-3-geospatial to version 3.6.0-r0.
  • Update opensearch-3-index-management to version 3.6.0-r0.
  • Update opensearch-3-job-scheduler to version 3.6.0-r0.
  • Update opensearch-3-k-nn to version 3.6.0-r0.
  • Update opensearch-3-ml-commons to version 3.6.0-r0.
  • Update opensearch-3-neural-search to version 3.6.0-r0.
  • Update opensearch-3-notifications to version 3.6.0-r0.
  • Update opensearch-3-observability to version 3.6.0-r0.
  • Update opensearch-3-opensearch-learning-to-rank-base to version 3.6.0-r0.
  • Update opensearch-3-opensearch-system-templates to version 3.6.0-r0.
  • Update opensearch-3-performance-analyzer to version 3.6.0-r0.
  • Update opensearch-3-query-insights to version 3.6.0-r0.
  • Update opensearch-3-reporting to version 3.6.0-r0.
  • Update opensearch-3-security to version 3.6.0-r0.
  • Update opensearch-3-security-analytics to version 3.6.0-r0.
  • Update opensearch-3-skills to version 3.6.0-r0.
  • Update opensearch-3-sql to version 3.6.0-r0.
  • Update opensearch-3-advanced-compat to version 3.6.0-r0.
Affected software
VendorProductAffected versionsFix available
opensearch-3 <= 3.6.0-r0 3.6.0-r0
opensearch-3-oci-entrypoint <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-icu <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-kuromoji <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-nori <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-phonetic <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-smartcn <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-stempel <= 3.6.0-r0 3.6.0-r0
opensearch-3-analysis-ukrainian <= 3.6.0-r0 3.6.0-r0
opensearch-3-crypto-kms <= 3.6.0-r0 3.6.0-r0
opensearch-3-discovery-azure-classic <= 3.6.0-r0 3.6.0-r0
opensearch-3-discovery-ec2 <= 3.6.0-r0 3.6.0-r0
opensearch-3-discovery-gce <= 3.6.0-r0 3.6.0-r0
opensearch-3-ingest-attachment <= 3.6.0-r0 3.6.0-r0
opensearch-3-mapper-annotated-text <= 3.6.0-r0 3.6.0-r0
opensearch-3-mapper-murmur3 <= 3.6.0-r0 3.6.0-r0
opensearch-3-mapper-size <= 3.6.0-r0 3.6.0-r0
opensearch-3-repository-azure <= 3.6.0-r0 3.6.0-r0
opensearch-3-repository-gcs <= 3.6.0-r0 3.6.0-r0
opensearch-3-repository-s3 <= 3.6.0-r0 3.6.0-r0
opensearch-3-store-smb <= 3.6.0-r0 3.6.0-r0
opensearch-3-telemetry-otel <= 3.6.0-r0 3.6.0-r0
opensearch-3-alerting <= 3.6.0-r0 3.6.0-r0
opensearch-3-anomaly-detection <= 3.6.0-r0 3.6.0-r0
opensearch-3-asynchronous-search <= 3.6.0-r0 3.6.0-r0
opensearch-3-cross-cluster-replication <= 3.6.0-r0 3.6.0-r0
opensearch-3-custom-codecs <= 3.6.0-r0 3.6.0-r0
opensearch-3-flow-framework <= 3.6.0-r0 3.6.0-r0
opensearch-3-geospatial <= 3.6.0-r0 3.6.0-r0
opensearch-3-index-management <= 3.6.0-r0 3.6.0-r0
opensearch-3-job-scheduler <= 3.6.0-r0 3.6.0-r0
opensearch-3-k-nn <= 3.6.0-r0 3.6.0-r0
opensearch-3-ml-commons <= 3.6.0-r0 3.6.0-r0
opensearch-3-neural-search <= 3.6.0-r0 3.6.0-r0
opensearch-3-notifications <= 3.6.0-r0 3.6.0-r0
opensearch-3-observability <= 3.6.0-r0 3.6.0-r0
opensearch-3-opensearch-learning-to-rank-base <= 3.6.0-r0 3.6.0-r0
opensearch-3-opensearch-system-templates <= 3.6.0-r0 3.6.0-r0
opensearch-3-performance-analyzer <= 3.6.0-r0 3.6.0-r0
opensearch-3-query-insights <= 3.6.0-r0 3.6.0-r0
opensearch-3-reporting <= 3.6.0-r0 3.6.0-r0
opensearch-3-security <= 3.6.0-r0 3.6.0-r0
opensearch-3-security-analytics <= 3.6.0-r0 3.6.0-r0
opensearch-3-skills <= 3.6.0-r0 3.6.0-r0
opensearch-3-sql <= 3.6.0-r0 3.6.0-r0
opensearch-3-advanced-compat <= 3.6.0-r0 3.6.0-r0
Original title
MINI-whc8-crc9-hcjp
Published: 8 Apr 2026 · Updated: 9 Apr 2026 · First seen: 9 Apr 2026