ID:5914 - Exploit for Improper Authentication in WP Like Button - CVE-2019-13344

 
Main Vulnerability Database Exploits ID:5914 - Exploit for Improper Authentication in WP Like Button - CVE-2019-13344

ID:5914 - Exploit for Improper Authentication in WP Like Button - CVE-2019-13344

Published: June 17, 2021


Vulnerability identifier: #VU19202
Vulnerability risk: Medium
CVE-ID: CVE-2019-13344
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
WP Like Button

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the "contains()" function in "wp_like_button.php" does not check if the current request is made by an authorized user. A remote attacker can bypass authentication process and update the settings of the plugin.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.