S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24150 Scanner

CVE-2021-24150 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in LikeBtn plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24150
7.5
CVSS

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Like Button Rating ♥ LikeBtn
AFFECTED< 2.6.32SAFE ✓≥ 2.6.32
Updated Aug 21, 2026View on NVD →
Detail

The LikeBtn WordPress plugin is a feature-rich tool that enables website owners to add a 'like' button feature on their content, allowing visitors to express their appreciation for articles, blog posts, and other forms of multimedia. The LikeBtn plugin is a must-have for people who aspire to have a more interactive website that encourages users' engagement. With its user-friendly interface and customizable design, LikeBtn is utilized by millions of websites globally as a way of engaging with their website visitors.

However, in recent times, a severe vulnerability (CVE-2021-24150) has been identified in the LikeBtn plugin, exposing it to Unauthenticated Full-Read Server-Side Request Forgery (SSRF). This vulnerability can be triggered by an unauthorized user and can lead to a hacker gaining access to sensitive information that can be leveraged for malicious activities.

If exploited, the vulnerability in the LikeBtn plugin can result in a security breach where sensitive information may be accessed by unauthorized sources. This may lead to financial damage, data loss, and compromised intellectual property rights. Furthermore, the vulnerability can lead to full access to the server, allowing hackers to launch DDoS attacks or other types of malicious activities that can severely harm a website's reputation.

To conclude, the LikeBtn plugin for WordPress is a popular tool that enables website owners to increase user engagement on their websites. However, the vulnerability discovered in the plugin can lead to severe security breaches that could compromise sensitive information. By taking the necessary precautions and engaging professionals like s4e.io, website owners can safeguard their online assets and maintain their users' trust.

 

REFERENCES

Solution Advice

To protect their website from such vulnerabilities, website owners should consider taking the following precautions: 

  • First, update to the latest version of the LikeBtn plugin. This will help to mitigate any vulnerabilities that may have existed in previous versions. 
  • Implementing a web application firewall will help to filter any malicious requests directed towards the website. 
  • Regularly scan the website for any potential vulnerabilities or threats. 
  • Implement a strong password policy that would make it difficult for hackers to gain access via brute-force attacks. 
  • Engage professional cybersecurity firms like SecurityForEveryone.com for vulnerability assessments, penetration testing, and remediation plans to fortify your website's security posture.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24150 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in LikeBtn plugin for WordPress | S4E