Wphappycoders develops a WordPress plugin focused on user engagement features, specifically the Comments Like/Dislike extension that integrates into WordPress comment systems. The plugin's vulnerability profile centers on authorization-control weaknesses—incorrect and missing authorization checks—which are characteristic of access-gating flaws in user-facing plugins. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wphappycoders over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24379MEDIUM The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. T | Jun 21, 2021 | 5.3 | 19 | NO | NO |
CVE-2023-3244MEDIUM The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an A | Aug 17, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-25906MEDIUM Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2. | May 17, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wphappycoders.
Media articles that mention a CVE ID that affects a product developed by Wphappycoders — matched by CVE ID, not by vendor name.