The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-11857 The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:49:14.290Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-13T11:15:09.617

Modified: 2024-11-21T05:54:03.563

Link: CVE-2021-24945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.