Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown
CVE-2022-0641
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2021-24945
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
0
Attacker Value
Unknown
CVE-2021-23402
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
0
Attacker Value
Unknown
CVE-2021-24379
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side
0
Attacker Value
Unknown
CVE-2021-24150
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
0
Attacker Value
Unknown
CVE-2020-8799
Disclosure Date: May 05, 2020 (last updated February 21, 2025)
A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.
0
Attacker Value
Unknown
CVE-2015-9466
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
0
Attacker Value
Unknown
CVE-2019-13344
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
0
Attacker Value
Unknown
CVE-2018-14888
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
0
Attacker Value
Unknown
CVE-2018-1000508
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in allows unauthorised users to do almost anything an admin can. This attack appear to be exploitable via Admin must visit logs page. This vulnerability appears to have been fixed in 3.2.
0