plugin

I Recommend This Vulnerabilities

12 known security issues reported for the I Recommend This WordPress plugin. Most recent disclosed Nov 12, 2023.

1 critical 2 high 2 medium

Running I Recommend This on your site? Check whether your installed version is affected.

Scan your site free

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.9.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0.

Affected:
up to 3.9.1
Fixed in:
3.9.1
Disclosed:
Nov 12, 2023

CVE-2023-28696 on NVD →

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.9.0

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3.8.3 versions.

Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
May 16, 2023

CVE-2023-23673 on NVD →

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.7.3

unknown

[en] A vulnerability has been found in I Recommend This Plugin up to 3.7.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file dot-irecommendthis.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to version 3.7.3 is a...

Affected:
up to 3.7.3
Fixed in:
3.7.3
Disclosed:
Apr 20, 2023

CVE-2014-125099 on NVD →

I Recommend This <= 3.8.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The I Recommend This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...

CVSS:
4.4
Affected:
up to 3.8.3
Fixed in:
3.9.0
Disclosed:
Apr 19, 2023

CVE-2023-23673 on NVD →

I Recommend This <= 3.9.0 - Cross-Site Request Forgery

medium

The I Recommend This plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.0. This is due to missing nonce validation on the ajax_callback function. This makes it possible for unauthenticated attackers to modify the plugins settings granted they can trick a site administ...

CVSS:
4.3
Affected:
up to 3.9.0
Fixed in:
3.9.1
Disclosed:
Mar 22, 2023

CVE-2023-28696 on NVD →

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.7.3

unknown

[en] The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

Affected:
up to 3.7.3
Fixed in:
3.7.3
Disclosed:
Aug 16, 2019

CVE-2014-10376 on NVD →

I Recommend This < 3.8.2 - Cross-Site Scripting

high

The I Recommend This plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Sep 11, 2018

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.8.2

unknown

The I Recommend This plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Sep 11, 2018

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.7.8

unknown

Authenticated SQL Injection vulnerability found by Paul Dannewitz in WordPress I Recommend This plugin version 3.7.7 and earlier versions. A user with the lowest privileges (for example subscriber) can execute SQLi through [dot_recommends] shortcode if the default value of check for IP addresses is activated. Patched v...

Affected:
up to 3.7.8
Fixed in:
3.7.8
Disclosed:
Aug 16, 2017

I Recommend This < 3.7.3 - SQL Injection

critical

The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

CVSS:
9.8
Affected:
up to 3.7.3
Fixed in:
3.7.3
Disclosed:
Sep 24, 2014

CVE-2014-10376 on NVD →

I Recommend This <= 3.7.2 - Authenticated (Subscriber+) SQL Injection via Shortcode

high

The I Recommend This plugin for WordPress is vulnerable to SQL Injection via the 'post_type' attribute called via the plugin's shortcode in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

CVSS:
8.8
Affected:
up to 3.7.2
Fixed in:
3.7.3
Disclosed:
Sep 24, 2014

CVE-2014-125099 on NVD →

I Recommend This – Love/Like Button for WordPress Posts [i-recommend-this] < 3.8.2

unknown

Plugin description: &quot;This plugin allows your visitors to simply like/recommend your posts instead of comment on it.&quot; Active installs (according to https://wordpress.org/plugins/i-recommend-this/): 40.000+ It&#039;s possible to inject SQL into the [dot_recommends] shortcode, if the check for IP addresses i...

Affected:
up to 3.8.2
Fixed in:
3.8.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database