Description
WordPress Plugin WP Like Button is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's settings. WordPress Plugin WP Like Button version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://limbenjamin.com/articles/wp-like-button-auth-bypass.html
https://www.exploit-db.com/exploits/47078
https://packetstormsecurity.com/files/153541/WordPress-Like-Button-1.6.0-Authentication-Bypass.html
Related Vulnerabilities
WordPress Plugin SpamTask Arbitrary File Upload (1.3.6)
Oracle Application Server Other Vulnerability (CVE-2006-5355)
Drupal Core 8.5.x Cross-Site Scripting (8.5.0 - 8.5.13)
WordPress Plugin HandL UTM Grabber Security Bypass (2.6.4)
Chamilo Improper Privilege Management Vulnerability (CVE-2022-27421)