Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown

CVE-2022-0641

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2021-24945

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
Attacker Value
Unknown

CVE-2021-23402

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
Attacker Value
Unknown

CVE-2021-24379

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side
Attacker Value
Unknown

CVE-2021-24150

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2020-8799

Disclosure Date: May 05, 2020 (last updated February 21, 2025)
A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.
Attacker Value
Unknown

CVE-2015-9466

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
Attacker Value
Unknown

CVE-2019-13344

Disclosure Date: July 05, 2019 (last updated November 27, 2024)
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
0
Attacker Value
Unknown

CVE-2018-14888

Disclosure Date: August 14, 2018 (last updated November 27, 2024)
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
0
Attacker Value
Unknown

CVE-2018-1000508

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in allows unauthorised users to do almost anything an admin can. This attack appear to be exploitable via Admin must visit logs page. This vulnerability appears to have been fixed in 3.2.
0