Impact
The Pro Like Button WordPress plugin before version 2.0 does not sanitize the 'postid' parameter before using it in a database query. An unauthenticated web user can supply a crafted value, causing the plugin to execute arbitrary SQL statements. This can lead to disclosure of sensitive data, modification or deletion of database contents, and potentially full compromise of the site if the database credentials have elevated privileges.
Affected Systems
Any WordPress site running the Pro Like Button plugin with a version older than 2.0 is affected. The specific version numbers are not listed, so any earlier release is potentially vulnerable.
Risk and Exploitability
The vulnerability is exploitable by anyone with access to the public site, as no authentication is required. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, but SQL injection remains a high‑risk issue in web applications. Without a mitigation, attackers can inject arbitrary SQL until they achieve their goal, and the impact is both confidentiality and integrity of the database.
OpenCVE Enrichment