plugin

Wp Like Button Vulnerabilities

3 known security issues reported for the Wp Like Button WordPress plugin. Most recent disclosed Nov 15, 2023.

2 medium 1 low

Running Wp Like Button on your site? Check whether your installed version is affected.

Scan your site free

WP Like Button <= 1.7.0 - Missing Authorization via crublabFBLBAjax

low

The WP Like Button plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the crublabFBLBAjax function in versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable and disable the like...

CVSS:
3.1
Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Nov 15, 2023

CVE-2023-47820 on NVD →

WP Like Button <= 1.6.11 - Cross-Site Request Forgery via 'saveData'

medium

The WP Like Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the 'saveData' function. This makes it possible for unauthenticated attackers to save button options via a forged request granted they can...

CVSS:
4.3
Affected:
up to 1.6.11
Fixed in:
1.7.0
Disclosed:
Aug 11, 2023

CVE-2023-40199 on NVD →

WP Like Button <= 1.6.0 - Missing Authorization

medium

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to success...

CVSS:
5.3
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Jul 5, 2019

CVE-2019-13344 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database