plugin

Wp Ulike Vulnerabilities

18 known security issues reported for the Wp Ulike WordPress plugin. Most recent disclosed Mar 10, 2026.

3 high 15 medium

Running Wp Ulike on your site? Check whether your installed version is affected.

Scan your site free

WP ULike - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute vulnerability

CVSS:
6.5
Affected:
up to 5.0.1
Fix:
No patched version reported
Disclosed:
Mar 10, 2026

WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute

medium

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due to the use of `html_entity_decode()` on shortcode attributes without subsequent output sanitization, which effectively by...

CVSS:
6.4
Affected:
up to 5.0.1
Fixed in:
5.0.2
Disclosed:
Mar 10, 2026

CVE-2026-2358 on NVD →

WP ULike <= 4.8.3.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter

medium

The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.8.3.1. This is due to the `wp_ulike_delete_history_api` AJAX action not verifying that the log entry being deleted belongs to the current user. This makes it possible for authenticated attackers,...

CVSS:
5.3
Affected:
up to 4.8.3.1
Fixed in:
5.0.0
Disclosed:
Feb 2, 2026

CVE-2026-0909 on NVD →

WP ULike <= 4.7.9.1 - Missing Authorization to Unauthenticated Content Spoofing

medium

The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to content spoofing due to a missing capability check on a function in all versions up to, and including, 4.7.9.1. This makes it possible for unauthenticated attackers to spoof content.

CVSS:
5.3
Affected:
up to 4.7.9.1
Fixed in:
4.7.10
Disclosed:
Apr 4, 2025

CVE-2025-32259 on NVD →

WP ULike <= 4.7.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
4.4
Affected:
up to 4.7.5
Fixed in:
4.7.6
Disclosed:
Jan 23, 2025

CVE-2024-12770 on NVD →

WP ULike <= 4.7.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
4.4
Affected:
up to 4.7.6
Fixed in:
4.7.7
Disclosed:
Jan 14, 2025

CVE-2025-22738 on NVD →

WP ULike <= 4.7.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...

CVSS:
4.4
Affected:
up to 4.7.4
Fixed in:
4.7.5
Disclosed:
Oct 15, 2024

CVE-2024-7879 on NVD →

WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion

medium

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or incorrect nonce validation on the wp_ulike_delete_history_api() function. This makes it possible for unauthenticated attacke...

CVSS:
4.3
Affected:
up to 4.7.4
Fixed in:
4.7.5
Disclosed:
Oct 15, 2024

CVE-2024-9649 on NVD →

WP ULike <= 4.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 4.7.3
Fixed in:
4.7.4
Disclosed:
Sep 4, 2024

CVE-2024-7878 on NVD →

WP ULike 4.7.1 - 4.7.2 - Authenticated (Subscriber+) Stored-Cross-Site Scripting

medium

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first name field in versions 4.7.1 to 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access a...

CVSS:
6.4
Affected:
4.7.1 – 4.7.2
Fixed in:
4.7.2.1
Disclosed:
Aug 16, 2024

CVE-2024-6792 on NVD →

WP ULike <= 4.7.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP ULike – Most Advanced Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (button image) in all versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato...

CVSS:
4.4
Affected:
up to 4.7.0
Fixed in:
4.7.1
Disclosed:
Jul 3, 2024

CVE-2024-6094 on NVD →

WP ULike – Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes

high

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of suffic...

CVSS:
8.8
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Apr 26, 2024

CVE-2024-1797 on NVD →

WP ULike <= 4.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class' attribute. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Apr 26, 2024

CVE-2024-1572 on NVD →

WP ULike <= 4.6.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber...

CVSS:
6.4
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Apr 26, 2024

CVE-2024-1759 on NVD →

WP ULike <= 4.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...

CVSS:
6.4
Affected:
up to 4.6.8
Fixed in:
4.6.9
Disclosed:
Oct 12, 2023

CVE-2023-45640 on NVD →

WP ULike <= 4.6.4 - Race Condition

medium

The WP ULike plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 4.6.4. This can lead to unpredictable post rating changes when certain conditions are met.

CVSS:
4.3
Affected:
up to 4.6.4
Fixed in:
4.6.5
Disclosed:
Nov 24, 2022

CVE-2022-45842 on NVD →

WP ULike < 3.2 - Missing Authorization

high

The WP ULike plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ulike_logs_process function in versions before 3.2. This makes it possible for authenticated attackers with low-level privileges to delete any row of certain tables. This can also be exploited via Cross-S...

CVSS:
7.5
Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
May 14, 2018

CVE-2018-1000511 on NVD →

WP ULike < 3.2 - Cross-Site Scripting

high

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user supplied IP HTTP Headers parameter in versions up to 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...

CVSS:
7.2
Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
May 14, 2018

CVE-2018-1000508 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database