Main
Vulnerability Database
Exploits
ID:5914 - Exploit for Improper Authentication in WP Like Button - CVE-2019-13344
ID:5914 - Exploit for Improper Authentication in WP Like Button - CVE-2019-13344
Published: June 17, 2021
Vulnerability identifier: #VU19202
Vulnerability risk: Medium
CVE-ID: CVE-2019-13344
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
WP Like Button
WP Like Button
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the "contains()" function in "wp_like_button.php" does not check if the current request is made by an authorized user. A remote attacker can bypass authentication process and update the settings of the plugin.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.