mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
18 lines
881 B
Markdown
18 lines
881 B
Markdown
### [CVE-2021-24945](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24945)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/d7618061-a7fa-4da4-9384-be19bc5e8548
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
|