← Back to CVE List

CVE-2021-24945

Published: 2021-12-13T11:15Z
Last Modified: 2024-11-21T05:54Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Like Button Rating ? LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt