Impact
A missing authorization flaw in Alimir’s WP ULike plugin allows an attacker to spoof content, impersonating other users or otherwise altering the appearance of posts and interactions. The vulnerability is categorized as CWE‑862, meaning the system does not correctly enforce permission checks before permitting modification or display of data. Exploiting this weakness could enable an attacker to render improbable interactions, potentially misleading site visitors or manipulating engagement metrics.
Affected Systems
Alimir WP ULike plugin versions from the earliest releases through 4.7.9.1 are affected. Users running any of these releases should verify the installed version and compare it to the latest release, which is newer than 4.7.9.1.
Risk and Exploitability
The CVSS score of 5.3 rates the vulnerability as medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves using the plugin’s endpoints that are accessible to authenticated users; however, the absence of proper permission checks means attackers with basic access can perform content spoofing without elevated privileges. Mitigation therefore requires ensuring that the plugin is patched or disabled to eliminate the missing authorization issue.
OpenCVE Enrichment
EUVD