CVE-2026-13347: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in templatic1 Hide My WP Lite
The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the HTTP response. Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of arbitrary file contents. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the affected site's server (such as wp-config). Note: The exploit requires the Elementor plugin and the 'Hide Elementor' feature to be enabled.
AI Analysis
Technical Summary
CVE-2026-13347 is a path traversal vulnerability (CWE-22) in the Hide My WP Lite WordPress plugin (up to version 1.3). The elementor_assets_filter() function processes user-supplied he_wrapper_js and he_wrapper_css query parameters by concatenating them directly onto the ABSPATH constant and passing the result to file_get_contents() without any path traversal validation, allow-listing, realpath containment checks, or extension restrictions. Although the output is filtered through wp_kses_post(), this only sanitizes HTML tags and does not prevent disclosure of arbitrary file contents. This allows unauthenticated attackers to read arbitrary files on the server, including sensitive configuration files. The exploit requires the Elementor plugin and the 'Hide Elementor' feature to be enabled.
Potential Impact
An unauthenticated attacker can read arbitrary files on the affected server, potentially exposing sensitive information such as database credentials stored in wp-config.php. This confidentiality breach does not affect integrity or availability directly but can facilitate further attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, disable the 'Hide Elementor' feature or the Hide My WP Lite plugin if possible. Restrict access to the affected endpoints and monitor for suspicious requests targeting the he_wrapper_js and he_wrapper_css parameters. Avoid exposing the Elementor plugin and Hide My WP Lite plugin to untrusted users.
CVE-2026-13347: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in templatic1 Hide My WP Lite
Description
The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the HTTP response. Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of arbitrary file contents. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the affected site's server (such as wp-config). Note: The exploit requires the Elementor plugin and the 'Hide Elementor' feature to be enabled.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13347 is a path traversal vulnerability (CWE-22) in the Hide My WP Lite WordPress plugin (up to version 1.3). The elementor_assets_filter() function processes user-supplied he_wrapper_js and he_wrapper_css query parameters by concatenating them directly onto the ABSPATH constant and passing the result to file_get_contents() without any path traversal validation, allow-listing, realpath containment checks, or extension restrictions. Although the output is filtered through wp_kses_post(), this only sanitizes HTML tags and does not prevent disclosure of arbitrary file contents. This allows unauthenticated attackers to read arbitrary files on the server, including sensitive configuration files. The exploit requires the Elementor plugin and the 'Hide Elementor' feature to be enabled.
Potential Impact
An unauthenticated attacker can read arbitrary files on the affected server, potentially exposing sensitive information such as database credentials stored in wp-config.php. This confidentiality breach does not affect integrity or availability directly but can facilitate further attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, disable the 'Hide Elementor' feature or the Hide My WP Lite plugin if possible. Restrict access to the affected endpoints and monitor for suspicious requests targeting the he_wrapper_js and he_wrapper_css parameters. Avoid exposing the Elementor plugin and Hide My WP Lite plugin to untrusted users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-25T14:32:04.252Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a50a3b368715ace433bd379
Added to database: 07/10/2026, 07:48:03 UTC
Last enriched: 07/17/2026, 09:45:47 UTC
Last updated: 08/24/2026, 22:52:08 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.