Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.54
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in LikeBtn Like Button Rating allows Cross-Site Scripting (XSS).This issue affects Like Button Rating: from n/a through 2.6.54.
- Affected:
- up to 2.6.54
- Fixed in:
- 2.6.54
- Disclosed:
- Sep 17, 2024
CVE-2024-44064 on NVD →
Like Button Rating <= 2.6.53 - Cross-Site Request Forgery
medium
The Like Button Rating ♥ LikeBtn plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.53. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they...
- CVSS:
- 6.1
- Affected:
- up to 2.6.53
- Fixed in:
- 2.6.54
- Disclosed:
- Aug 29, 2024
CVE-2024-44064 on NVD →
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.45
unknown
[en] The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
- Affected:
- up to 2.6.45
- Fixed in:
- 2.6.45
- Disclosed:
- Jun 13, 2022
CVE-2022-0745 on NVD →
Like Button Rating ♥ LikeBtn <= 2.6.44 - Arbitrary e-mail Sending
medium
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
- CVSS:
- 5
- Affected:
- up to 2.6.44
- Fixed in:
- 2.6.45
- Disclosed:
- May 23, 2022
CVE-2022-0745 on NVD →
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.38
unknown
[en] The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
- Affected:
- up to 2.6.38
- Fixed in:
- 2.6.38
- Disclosed:
- Dec 13, 2021
CVE-2021-24945 on NVD →
Like Button Rating <= 2.6.37 - Unauthorised Vote Export to Email & IP Addresses Disclosure
medium
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
- CVSS:
- 6.5
- Affected:
- up to 2.6.37
- Fixed in:
- 2.6.38
- Disclosed:
- Nov 11, 2021
CVE-2021-24945 on NVD →
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.32
unknown
[en] The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
- Affected:
- up to 2.6.32
- Fixed in:
- 2.6.32
- Disclosed:
- Apr 5, 2021
CVE-2021-24150 on NVD →
Like Button Rating ♥ LikeBtn < 2.6.32 - Server-Side Request Forgery
high
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
- CVSS:
- 7.5
- Affected:
- up to 2.6.32
- Fixed in:
- 2.6.32
- Disclosed:
- Feb 6, 2021
CVE-2021-24150 on NVD →
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.32
unknown
Unauthenticated Server-Side Request Forgery (SSRF) vulnerability found by Lauritz Holme in WordPress Like Button Rating plugin (versions <= 2.6.31).
- Affected:
- up to 2.6.32
- Fixed in:
- 2.6.32
- Disclosed:
- Feb 6, 2021
Like Button Rating <= 2.5.3 - Arbitrary Settings Change
medium
The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the 'init' action in versions up to, and including, 2.5.3. This makes it possible for unauthenticated attackers to modify the vulnerable site's settings.
- CVSS:
- 6.5
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Nov 2, 2017
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.5.4
unknown
The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the 'init' action in versions up to, and including, 2.5.3. This makes it possible for unauthenticated attackers to modify the vulnerable site's settings.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Nov 2, 2017
Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.5.4
unknown
In the init action, this plugin checked to see if $_POST['likebtn_import_config'] is empty. If it’s not empty then it base64-decodes the string, parses it as JSON, and starts changing options. This could allow attackers to change blog settings such as the Site Title.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database