Impact
Subscriber SQL injection in Like Button Rating plugin versions 2.6.61 and earlier allows an attacker to influence the SQL queries executed by the plugin. This vulnerability can lead to unauthorized database access, data leakage, or modification of site content. The weakness is a classic input validation flaw documented as CWE-89.
Affected Systems
WordPress Like Button Rating plugin (vendor LikeBtn) versions up to 2.6.61 are affected. The plugin is available for WordPress sites and is used for rating and liking content. No additional version information is provided beyond the version cutoff.
Risk and Exploitability
CVSS score 8.5 indicates high severity. The EPSS score is not provided, so the current estimate of exploitation probability is unknown. The vulnerability is not listed in CISA KEV. Attackers can exploit it through crafted requests to the plugin's endpoints; any authenticated or unauthenticated user who can submit a like or rating can potentially inject arbitrary SQL.
OpenCVE Enrichment