Likebtn operates a narrowly scoped web-based rating and social-engagement widget whose vulnerability surface reflects the attack surface of client-side embedded scripts and server-side form handling. The durable signal centers on application-layer input and authorization weaknesses—cross-site request forgery, cross-site scripting, missing authorization, and exposure of sensitive information—characteristic of web components that interact directly with user input and session state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Likebtn over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24945HIGH The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authe | Dec 13, 2021 | 8.0 | 25 | NO | NO |
CVE-2022-0745MEDIUM The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body | Jun 13, 2022 | 6.5 | 22 | NO | NO |
CVE-2024-44064MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.This issue affects Like Button | Sep 17, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Likebtn.
Media articles that mention a CVE ID that affects a product developed by Likebtn — matched by CVE ID, not by vendor name.