Vulnerability record · CVE-2019-13344 · published 5 July 2019
CVE-2019-13344: WordPress WP Like Button plugin auth bypass allows unauthenticated settings change
Crudlab · Wp Like Button
The CRUDLab WP Like Button plugin through 1.6.0 for WordPress has an authentication bypass in the contains() function in wp_like_button.php, which fails to verify that the request comes from an authorized user. Any unauthenticated visitor can therefore update the plugin's settings, including the each_page_url and code_snippet parameters. The flaw matters because it lets anonymous users alter site configuration without credentials.
Description
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
medium priorityThe flaw allows unauthenticated settings modification but is limited to low integrity impact with no confidentiality or availability effect, and no KEV listing.
What it is
The CRUDLab WP Like Button plugin through 1.6.0 for WordPress has an authentication bypass in the contains() function in wp_like_button.php, which fails to verify that the request comes from an authorized user. Any unauthenticated visitor can therefore update the plugin's settings, including the each_page_url and code_snippet parameters. The flaw matters because it lets anonymous users alter site configuration without credentials.
Impact
An attacker gains the ability to modify plugin settings, including the each_page_url and code_snippet values, without authentication. The CVSS vector rates only low integrity impact with no confidentiality or availability effect.
Attack surface
Reachable over the network via the WordPress admin endpoint wp-admin/admin.php?page=facebook-like-button, using the each_page_url or code_snippet parameters. No authentication and no user interaction are required per the CVSS vector (PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but public exploit write-ups are referenced (Packet Storm and limbenjamin.com tagged Exploit), and EPSS is high at 0.45095 (98.7th percentile), indicating elevated likelihood of exploitation.
What to do
- Update the WP Like Button plugin beyond version 1.6.0, or remove it if no fixed release is available.
- If the plugin cannot be updated or removed, deactivate it to eliminate the exposed admin endpoint.
- Restrict access to wp-admin/admin.php and plugin admin pages at the web server or WAF where feasible.
- Audit plugin settings for unauthorized changes to each_page_url and code_snippet.
- Monitor plugin vendor release notes for a patched version.
Detection
- Review web logs for unauthenticated requests to wp-admin/admin.php?page=facebook-like-button, especially with each_page_url or code_snippet parameters.
- Alert on POST requests to that admin page lacking a valid authenticated WordPress session.
- Compare current plugin settings against known-good values to spot unauthorized modifications.
- Watch for requests from IPs with no prior authenticated activity hitting plugin admin endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/153541/WordPress-Like-Button-1.6.0-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://limbenjamin.com/articles/wp-like-button-auth-bypass.html | ExploitThird Party Advisory |
| https://wordpress.org/plugins/wp-like-button/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/9432 | |
| http://packetstormsecurity.com/files/153541/WordPress-Like-Button-1.6.0-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://limbenjamin.com/articles/wp-like-button-auth-bypass.html | ExploitThird Party Advisory |
| https://wordpress.org/plugins/wp-like-button/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/9432 |
Track CVE-2019-13344 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-13344), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.