CVE-2021-24150
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 4.4%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
05 Apr 2021Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
Affected products
Unknown · Like Button Rating ♥ LikeBtnWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →