Like Button Rating <= 2.6.37 - Unauthorised Vote Export to Email & IP Addresses Disclosure

2021-11-11 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 2.6.38
Affected Version<= 2.6.37
CVSS6.5Medium
CVECVE-2021-24945
View all Like Button Rating ♥ LikeBtn vulnerabilities

Vulnerability Overview

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

Technical Analysis

REMEDIATION: Update to version 2.6.38, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C