CVE-2019-13344
MEDIUMCrudlab WP Like Button < 1.6.0 - Missing Authentication
Title source: ruleDescription
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
Exploits (1)
References (4)
Scores
CVSS v3
5.3
EPSS
0.5806
EPSS Percentile
98.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-306
Status
published
Products (1)
crudlab/wp_like_button
< 1.6.0
Published
Jul 05, 2019
Tracked Since
Feb 18, 2026