Description
WordPress Plugin WP Like Button is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's settings. WordPress Plugin WP Like Button version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://limbenjamin.com/articles/wp-like-button-auth-bypass.html
https://www.exploit-db.com/exploits/47078
https://packetstormsecurity.com/files/153541/WordPress-Like-Button-1.6.0-Authentication-Bypass.html
Related Vulnerabilities
OpenSSL Key Management Errors Vulnerability (CVE-2016-7055)
WordPress Plugin Csv2WPeC Coupon Arbitrary File Upload (1.1)
Jboss EAP CVE-2013-1862 Vulnerability (CVE-2013-1862)
WordPress Plugin WP-Members Membership Cross-Site Scripting (3.1.4.2)
WordPress Plugin Zip Attachments Arbitrary File Download (1.4)