WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
Solution:
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.