Like Button Rating <= 2.6.37 - Unauthorised Vote Export to Email & IP Addresses Disclosure
2021-11-11 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 2.6.38
Affected PluginLike Button Rating ♥ LikeBtn
Affected Version
<= 2.6.37CVSS6.5Medium
CVE
CVE-2021-24945Vulnerability Overview
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
Technical Analysis
REMEDIATION: Update to version 2.6.38, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C