Description
WordPress Plugin WP Like Button is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's settings. WordPress Plugin WP Like Button version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://limbenjamin.com/articles/wp-like-button-auth-bypass.html
https://www.exploit-db.com/exploits/47078
https://packetstormsecurity.com/files/153541/WordPress-Like-Button-1.6.0-Authentication-Bypass.html
Related Vulnerabilities
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-3814)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5488)
WordPress 4.7.x Arbitrary File Deletion Vulnerability (4.7 - 4.7.10)
Internet Information Services Other Vulnerability (CVE-1999-1223)
WordPress Plugin Weaver Show Posts Cross-Site Scripting (1.6)