Impact
The WP ULike WordPress plugin is vulnerable to insecure direct object reference, allowing an authenticated user with Subscriber level access and above to delete arbitrary log entries belonging to other users via the 'id' parameter. This flaw leads to loss or tampering of user activity logs and violates the integrity of stored data, corresponding to CWE-639.
Affected Systems
All installations of the WP ULike plugin up to and including version 4.8.3.1 are affected. The plugin is available for WordPress sites and is identified as alimir:WP ULike – Like & Dislike Buttons for Engagement and Feedback.
Risk and Exploitability
The vulnerability has a CVSS base score of 5.3, placing it in the moderate severity range. The EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The flaw is not present in the CISA KEV catalog. Exploitation requires an authenticated account with the 'stats' capability; attackers can trigger the delete action via the wp_ulike_delete_history_api AJAX endpoint.
OpenCVE Enrichment