.. / CVE-2021-24150

Exploit for WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery (CVE-2021-24150)

Description:

WordPress Like Button Rating plugin before 2.6.32 is susceptible to server-side request forgery. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2021-24150.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24150.yaml
Copy

References:

https://wpscan.com/vulnerability/6bc6023f-a5e7-4665-896c-95afa5b638fb
https://wordpress.org/plugins/likebtn-like-button/
https://nvd.nist.gov/vuln/detail/CVE-2021-24150