4.3
CVSSv3

CVE-2023-3244

Published: 17/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: After attempting to contact the developer with no response, and reporting this to the WordPress plugin's team 30 days ago we are disclosing this issue as it still is not updated.

Vulnerable Product Search on Vulmon Subscribe to Product

wphappycoders comments like dislike

Exploits

WordPress Comments Like Dislike plugin versions 120 and below suffer from a missing capability check on the restore_settings function that allows an attacker to reset the plugin's settings ...

Github Repositories

This is a Proof of Concept (PoC) for CVE-2023-3244, a vulnerability in comment-like-dislike. The PoC demonstrates the exploitability of this vulnerability and serves as a reference for security researchers and developers to better understand and mitigate the risk associated with this issue.

Hello, this is a simple Proof of Concept (PoC) for the CVE-2023-3244 vulnerability found in the WordPress plugin "comments-like-dislike" The vulnerability affects plugin versions up to and including 120 To exploit this vulnerability, you can refer to the Python script provided However, please note that the issue has been addressed and fixed in version 121 of th