Wpulike is a WordPress plugin focused on engagement and rating functionality, with a modest but persistent vulnerability footprint concentrated in cross-site scripting, CSRF, SQL injection, and permission-assignment flaws. These weakness classes are typical of web-application input-handling and access-control logic, and reflect the plugin's direct interaction with user-submitted data and WordPress permission boundaries. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpulike over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1797HIGH The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ | May 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2018-1000511HIGH WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody to delete any row in certain tables. This attack appear to b | Jun 26, 2018 | 7.5 | 21 | NO | NO |
CVE-2024-1759MEDIUM The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and incl | May 2, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-1572MEDIUM The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient | May 2, 2024 | 5.4 | 16 | NO | NO |
CVE-2018-1000508MEDIUM WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in allows unauthorised users to do almost anything an admin can. | Jun 26, 2018 | 4.8 | 16 | NO | NO |
CVE-2025-22738MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alimir WP ULike wp-ulike allows Stored XSS.This issue affects WP ULike: from n | Jan 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2024-9649MEDIUM The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is du | Oct 16, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpulike.
Media articles that mention a CVE ID that affects a product developed by Wpulike — matched by CVE ID, not by vendor name.