← back
CVE-2021-24150

Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF

EPSS 4.4%CWE-918
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 4.4%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
05 Apr 2021Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →