plugin

Likebtn Like Button Vulnerabilities

12 known security issues reported for the Likebtn Like Button WordPress plugin. Most recent disclosed Sep 17, 2024.

1 high 4 medium

Running Likebtn Like Button on your site? Check whether your installed version is affected.

Scan your site free

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.54

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in LikeBtn Like Button Rating allows Cross-Site Scripting (XSS).This issue affects Like Button Rating: from n/a through 2.6.54.

Affected:
up to 2.6.54
Fixed in:
2.6.54
Disclosed:
Sep 17, 2024

CVE-2024-44064 on NVD →

Like Button Rating <= 2.6.53 - Cross-Site Request Forgery

medium

The Like Button Rating ♥ LikeBtn plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.53. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they...

CVSS:
6.1
Affected:
up to 2.6.53
Fixed in:
2.6.54
Disclosed:
Aug 29, 2024

CVE-2024-44064 on NVD →

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.45

unknown

[en] The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body

Affected:
up to 2.6.45
Fixed in:
2.6.45
Disclosed:
Jun 13, 2022

CVE-2022-0745 on NVD →

Like Button Rating ♥ LikeBtn <= 2.6.44 - Arbitrary e-mail Sending

medium

The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body

CVSS:
5
Affected:
up to 2.6.44
Fixed in:
2.6.45
Disclosed:
May 23, 2022

CVE-2022-0745 on NVD →

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.38

unknown

[en] The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

Affected:
up to 2.6.38
Fixed in:
2.6.38
Disclosed:
Dec 13, 2021

CVE-2021-24945 on NVD →

Like Button Rating <= 2.6.37 - Unauthorised Vote Export to Email & IP Addresses Disclosure

medium

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

CVSS:
6.5
Affected:
up to 2.6.37
Fixed in:
2.6.38
Disclosed:
Nov 11, 2021

CVE-2021-24945 on NVD →

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.32

unknown

[en] The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

Affected:
up to 2.6.32
Fixed in:
2.6.32
Disclosed:
Apr 5, 2021

CVE-2021-24150 on NVD →

Like Button Rating ♥ LikeBtn < 2.6.32 - Server-Side Request Forgery

high

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

CVSS:
7.5
Affected:
up to 2.6.32
Fixed in:
2.6.32
Disclosed:
Feb 6, 2021

CVE-2021-24150 on NVD →

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.6.32

unknown

Unauthenticated Server-Side Request Forgery (SSRF) vulnerability found by Lauritz Holme in WordPress Like Button Rating plugin (versions <= 2.6.31).

Affected:
up to 2.6.32
Fixed in:
2.6.32
Disclosed:
Feb 6, 2021

Like Button Rating <= 2.5.3 - Arbitrary Settings Change

medium

The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the 'init' action in versions up to, and including, 2.5.3. This makes it possible for unauthenticated attackers to modify the vulnerable site's settings.

CVSS:
6.5
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Nov 2, 2017

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.5.4

unknown

The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the 'init' action in versions up to, and including, 2.5.3. This makes it possible for unauthenticated attackers to modify the vulnerable site's settings.

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Nov 2, 2017

Like Button Rating ♥ LikeBtn [likebtn-like-button] < 2.5.4

unknown

In the init action, this plugin checked to see if $_POST[&#039;likebtn_import_config&#039;] is empty. If it&rsquo;s not empty then it base64-decodes the string, parses it as JSON, and starts changing options. This could allow attackers to change blog settings such as the Site Title.

Affected:
up to 2.5.4
Fixed in:
2.5.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database