WP Like Button <= 1.7.0 - Missing Authorization via crublabFBLBAjax
low
The WP Like Button plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the crublabFBLBAjax function in versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable and disable the like...
- CVSS:
- 3.1
- Affected:
- up to 1.7.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 15, 2023
CVE-2023-47820 on NVD →
WP Like Button <= 1.6.11 - Cross-Site Request Forgery via 'saveData'
medium
The WP Like Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the 'saveData' function. This makes it possible for unauthenticated attackers to save button options via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 1.6.11
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 11, 2023
CVE-2023-40199 on NVD →
WP Like Button <= 1.6.0 - Missing Authorization
medium
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to success...
- CVSS:
- 5.3
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Jul 5, 2019
CVE-2019-13344 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database