vendor:
WP Like Button
by:
Benjamin Lim
5.3
CVSS
MEDIUM
Authentication Bypass
287
CWE
Product Name: WP Like Button
Affected Version From: 1.5.0
Affected Version To: 1.6.0
Patch Exists: NO
Related CWE: CVE-2019-13344
CPE: 2.3:a:wp_like_button:wp_like_button:1.6.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
WP Like Button 1.6.0 – Auth Bypass
Authentication Bypass vulnerability in the WP Like Button (Free) plugin version 1.6.0 allows unauthenticated attackers to change the settings of the plugin. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the settings of the plugin.
Mitigation:
Users are advised to switch to a different plugin.