5.3

CVE-2021-24379

Exploit

Comments Like Dislike < 1.1.4 - Add Like/Dislike Bypass

Comments Like Dislike <= 1.1.2 - Add Like/Dislike Bypass

The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side
Mögliche Gegenmaßnahme
Comments Like Dislike: Update to version 1.1.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WphappycodersComments Like Dislike SwPlatformwordpress Version < 1.1.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Comments Like Dislike
Version [*, 1.1.4)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.576
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://wpscan.com/vulnerability/aae7a889-195c-45a3-bbe4-e6d4cd2d7fd9
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/f71e60b9-68e9-408a-8047-7f74b7fb72b2
Third Party Advisory