CVE-2021-24150
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
Record summary
CVE-2021-24150 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Like Button Rating ♥ LikeBtn | CVE List | 2.6.32 to < 2.6.32 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Like Button Rating <2.6.32 - Server-Side Request ForgeryCVSS 7.5
WordPress Like Button Rating plugin before 2.6.32 is susceptible to server-side request forgery. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to make requests to internal resources, potentially leading to unauthorized access or information disclosure.
Remediation
Update the WordPress Like Button Rating plugin to version 2.6.32 or later.
Source: ProjectDiscovery