Like Button Rating <= 2.5.3 - Arbitrary Settings Change

2017-11-02 00:00
Tom Adams

Strategic Overview

Status
Patched in 2.5.4
Affected Version<= 2.5.3
CVSS6.5Medium
CVEN/A
View all Like Button Rating ♥ LikeBtn vulnerabilities

Vulnerability Overview

The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the 'init' action in versions up to, and including, 2.5.3. This makes it possible for unauthenticated attackers to modify the vulnerable site's settings.

Technical Analysis

REMEDIATION: Update to version 2.5.4, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C