WP ULike - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute vulnerability
- CVSS:
- 6.5
- Affected:
- up to 5.0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 10, 2026
WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute
medium
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due to the use of `html_entity_decode()` on shortcode attributes without subsequent output sanitization, which effectively by...
- CVSS:
- 6.4
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.2
- Disclosed:
- Mar 10, 2026
CVE-2026-2358 on NVD →
WP ULike <= 4.8.3.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter
medium
The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.8.3.1. This is due to the `wp_ulike_delete_history_api` AJAX action not verifying that the log entry being deleted belongs to the current user. This makes it possible for authenticated attackers,...
- CVSS:
- 5.3
- Affected:
- up to 4.8.3.1
- Fixed in:
- 5.0.0
- Disclosed:
- Feb 2, 2026
CVE-2026-0909 on NVD →
WP ULike <= 4.7.9.1 - Missing Authorization to Unauthenticated Content Spoofing
medium
The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to content spoofing due to a missing capability check on a function in all versions up to, and including, 4.7.9.1. This makes it possible for unauthenticated attackers to spoof content.
- CVSS:
- 5.3
- Affected:
- up to 4.7.9.1
- Fixed in:
- 4.7.10
- Disclosed:
- Apr 4, 2025
CVE-2025-32259 on NVD →
WP ULike <= 4.7.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 4.7.5
- Fixed in:
- 4.7.6
- Disclosed:
- Jan 23, 2025
CVE-2024-12770 on NVD →
WP ULike <= 4.7.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 4.7.6
- Fixed in:
- 4.7.7
- Disclosed:
- Jan 14, 2025
CVE-2025-22738 on NVD →
WP ULike <= 4.7.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.5
- Disclosed:
- Oct 15, 2024
CVE-2024-7879 on NVD →
WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion
medium
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or incorrect nonce validation on the wp_ulike_delete_history_api() function. This makes it possible for unauthenticated attacke...
- CVSS:
- 4.3
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.5
- Disclosed:
- Oct 15, 2024
CVE-2024-9649 on NVD →
WP ULike <= 4.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- Sep 4, 2024
CVE-2024-7878 on NVD →
WP ULike 4.7.1 - 4.7.2 - Authenticated (Subscriber+) Stored-Cross-Site Scripting
medium
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first name field in versions 4.7.1 to 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access a...
- CVSS:
- 6.4
- Affected:
- 4.7.1 – 4.7.2
- Fixed in:
- 4.7.2.1
- Disclosed:
- Aug 16, 2024
CVE-2024-6792 on NVD →
WP ULike <= 4.7.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP ULike – Most Advanced Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (button image) in all versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato...
- CVSS:
- 4.4
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.1
- Disclosed:
- Jul 3, 2024
CVE-2024-6094 on NVD →
WP ULike – Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes
high
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of suffic...
- CVSS:
- 8.8
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Apr 26, 2024
CVE-2024-1797 on NVD →
WP ULike <= 4.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class' attribute. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Apr 26, 2024
CVE-2024-1572 on NVD →
WP ULike <= 4.6.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber...
- CVSS:
- 6.4
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Apr 26, 2024
CVE-2024-1759 on NVD →
WP ULike <= 4.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 4.6.8
- Fixed in:
- 4.6.9
- Disclosed:
- Oct 12, 2023
CVE-2023-45640 on NVD →
WP ULike <= 4.6.4 - Race Condition
medium
The WP ULike plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 4.6.4. This can lead to unpredictable post rating changes when certain conditions are met.
- CVSS:
- 4.3
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.5
- Disclosed:
- Nov 24, 2022
CVE-2022-45842 on NVD →
WP ULike < 3.2 - Missing Authorization
high
The WP ULike plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ulike_logs_process function in versions before 3.2. This makes it possible for authenticated attackers with low-level privileges to delete any row of certain tables. This can also be exploited via Cross-S...
- CVSS:
- 7.5
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- May 14, 2018
CVE-2018-1000511 on NVD →
WP ULike < 3.2 - Cross-Site Scripting
high
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user supplied IP HTTP Headers parameter in versions up to 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 7.2
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- May 14, 2018
CVE-2018-1000508 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database