What the vulnerability does
01Description
Missing Authorization vulnerability in WP Happy Coders Posts Like Dislike allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Like Dislike: from n/a through 1.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
Posts Like Dislike through version 1.1.0 lacks proper authorization checks on like/dislike actions. An unauthenticated attacker can submit likes or dislikes on posts without permission, modifying post engagement metrics. The vulnerability requires no user interaction and is exploitable over the network.
What an attacker can do
03Attacker Capabilities
Submit likes or dislikes on posts without authentication or authorization.
Potential impact on your site
04Site Impact
Post like/dislike counts can be manipulated by anyone, compromising engagement metrics and user trust.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication required.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated