Description
The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Published: 2026-10-01
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Unauthenticated SQL Injection
Action: Patch Now
AI Analysis

Impact

The Pro Like Button WordPress plugin before version 2.0 does not sanitize the 'postid' parameter before using it in a database query. An unauthenticated web user can supply a crafted value, causing the plugin to execute arbitrary SQL statements. This can lead to disclosure of sensitive data, modification or deletion of database contents, and potentially full compromise of the site if the database credentials have elevated privileges.

Affected Systems

Any WordPress site running the Pro Like Button plugin with a version older than 2.0 is affected. The specific version numbers are not listed, so any earlier release is potentially vulnerable.

Risk and Exploitability

The vulnerability is exploitable by anyone with access to the public site, as no authentication is required. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, but SQL injection remains a high‑risk issue in web applications. Without a mitigation, attackers can inject arbitrary SQL until they achieve their goal, and the impact is both confidentiality and integrity of the database.

Generated by OpenCVE AI on October 1, 2026 at 07:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pro Like Button to version 2.0 or later, which sanitizes the 'postid' input.
  • Disable or uninstall the plugin if an upgrade is not possible.
  • Configure a web application firewall or modify the site’s .htaccess to block malicious 'postid' patterns and prevent SQL injection attempts.

Generated by OpenCVE AI on October 1, 2026 at 07:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Title Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:49.209Z

Reserved: 2026-09-11T13:13:27.557Z

Link: CVE-2026-89296

cve-icon Vulnrichment

Updated: 2026-10-01T10:43:31.620Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:14.337

Modified: 2026-10-01T11:17:29.220

Link: CVE-2026-89296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')