← Vulnerability feed

Vulnerability record · CVE-2019-13344 · published 5 July 2019

CVE-2019-13344: WordPress WP Like Button plugin auth bypass allows unauthenticated settings change

Crudlab · Wp Like Button

The CRUDLab WP Like Button plugin through 1.6.0 for WordPress has an authentication bypass in the contains() function in wp_like_button.php, which fails to verify that the request comes from an authorized user. Any unauthenticated visitor can therefore update the plugin's settings, including the each_page_url and code_snippet parameters. The flaw matters because it lets anonymous users alter site configuration without credentials.

5.3 CVSS 3.0 Medium EPSS 45% · top 1.3% CWE-306 · Missing authentication for critical function
5.3CVSS 3.0 base score, v2 5.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityThe flaw allows unauthenticated settings modification but is limited to low integrity impact with no confidentiality or availability effect, and no KEV listing.

What it is

The CRUDLab WP Like Button plugin through 1.6.0 for WordPress has an authentication bypass in the contains() function in wp_like_button.php, which fails to verify that the request comes from an authorized user. Any unauthenticated visitor can therefore update the plugin's settings, including the each_page_url and code_snippet parameters. The flaw matters because it lets anonymous users alter site configuration without credentials.

Impact

An attacker gains the ability to modify plugin settings, including the each_page_url and code_snippet values, without authentication. The CVSS vector rates only low integrity impact with no confidentiality or availability effect.

Attack surface

Reachable over the network via the WordPress admin endpoint wp-admin/admin.php?page=facebook-like-button, using the each_page_url or code_snippet parameters. No authentication and no user interaction are required per the CVSS vector (PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but public exploit write-ups are referenced (Packet Storm and limbenjamin.com tagged Exploit), and EPSS is high at 0.45095 (98.7th percentile), indicating elevated likelihood of exploitation.

What to do

  • Update the WP Like Button plugin beyond version 1.6.0, or remove it if no fixed release is available.
  • If the plugin cannot be updated or removed, deactivate it to eliminate the exposed admin endpoint.
  • Restrict access to wp-admin/admin.php and plugin admin pages at the web server or WAF where feasible.
  • Audit plugin settings for unauthorized changes to each_page_url and code_snippet.
  • Monitor plugin vendor release notes for a patched version.

Detection

  • Review web logs for unauthenticated requests to wp-admin/admin.php?page=facebook-like-button, especially with each_page_url or code_snippet parameters.
  • Alert on POST requests to that admin page lacking a valid authenticated WordPress session.
  • Compare current plugin settings against known-good values to spot unauthorized modifications.
  • Watch for requests from IPs with no prior authenticated activity hitting plugin admin endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-13344 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-40199Crudlab wp like button cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.EPSS 0.25%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed

Source: NIST National Vulnerability Database (record CVE-2019-13344), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.