Extension WordPress
Vulnérabilités WP ULike – Like & Dislike Buttons for Engagement and Feedback
Cette page rassemble les failles publiées pour WP ULike – Like & Dislike Buttons for Engagement and Feedback, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP ULike – Like & Dislike Buttons for Engagement and Feedback
17 fiches
WP ULike <= 5.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due to the use of `html_entity_decode()` on shortcode attributes without…
*-5.0.1
5.0.2
10/03/2026
WP ULike <= 4.8.3.1 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter
The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.8.3.1. This is due to the `wp_ulike_delete_history_api` AJAX action not verifying that the log entry being deleted belongs…
*-4.8.3.1
5.0.0
02/02/2026
WP ULike <= 4.7.9.1 – Missing Authorization to Unauthenticated Content Spoofing
The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to content spoofing due to a missing capability check on a function in all versions up to, and including, 4.7.9.1. This makes it possible for unauthenticated…
*-4.7.9.1
4.7.10
04/04/2025
WP ULike <= 4.7.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-4.7.5
4.7.6
23/01/2025
WP ULike <= 4.7.6 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-4.7.6
4.7.7
14/01/2025
WP ULike <= 4.7.4 – Cross-Site Request Forgery to Statistic Deletion
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or incorrect nonce validation on the…
*-4.7.4
4.7.5
15/10/2024
WP ULike <= 4.7.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it…
*-4.7.4
4.7.5
15/10/2024
WP ULike <= 4.7.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.3 due to insufficient input sanitization and output escaping.…
*-4.7.3
4.7.4
04/09/2024
WP ULike 4.7.1 – 4.7.2 – Authenticated (Subscriber+) Stored-Cross-Site Scripting
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first name field in versions 4.7.1 to 4.7.2 due to insufficient input sanitization and output escaping. This…
4.7.1-4.7.2
4.7.2.1
16/08/2024
WP ULike <= 4.7.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP ULike – Most Advanced Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (button image) in all versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping.…
*-4.7.0
4.7.1
03/07/2024
WP ULike <= 4.6.9 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output…
*-4.6.9
4.7.0
26/04/2024
WP ULike – Most Advanced WordPress Marketing Toolkit <= 4.6.9 – Authenticated (Contributor+) SQL Injection via Shortcodes
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due…
*-4.6.9
4.7.0
26/04/2024
WP ULike <= 4.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class'…
*-4.6.9
4.7.0
26/04/2024
WP ULike <= 4.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-4.6.8
4.6.9
12/10/2023
WP ULike <= 4.6.4 – Race Condition
The WP ULike plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 4.6.4. This can lead to unpredictable post rating changes when certain conditions are met.
*-4.6.4
4.6.5
24/11/2022
WP ULike < 3.2 – Missing Authorization
The WP ULike plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ulike_logs_process function in versions before 3.2. This makes it possible for authenticated attackers with low-level privileges to delete any…
[*, 3.2)
3.2
14/05/2018
WP ULike < 3.2 – Cross-Site Scripting
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user supplied IP HTTP Headers parameter in versions up to 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 3.2)
3.2
14/05/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.