Record summary

CVE-2021-24150 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Like Button Rating ♥ LikeBtn

CVE List2.6.32 to < 2.6.32affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Like Button Rating <2.6.32 - Server-Side Request ForgeryCVSS 7.5

WordPress Like Button Rating plugin before 2.6.32 is susceptible to server-side request forgery. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to make requests to internal resources, potentially leading to unauthorized access or information disclosure.

Remediation

Update the WordPress Like Button Rating plugin to version 2.6.32 or later.

WeaknessesCWE-918
Authorstheamanrawat
Template tagscve2021cvewordpresswp-pluginwpssrfwpscanunauthlikebtn-like-buttonlikebtn-like-button_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:likebtn-like-button_project:likebtn-like-button:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2