First published: Tue Jun 26 2018(Updated: )
WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody to delete any row in certain tables. This attack appear to be exploitable via Attacker must make AJAX request. This vulnerability appears to have been fixed in 3.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP ULike | =2.8.1 | |
WP ULike | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000511 is considered a high severity vulnerability due to its potential for unauthorized data manipulation.
To fix CVE-2018-1000511, upgrade WP ULike to version 3.2 or later.
CVE-2018-1000511 is categorized as an Incorrect Access Control vulnerability.
An attacker can exploit CVE-2018-1000511 to delete any row in specific tables via unauthorized AJAX requests.
CVE-2018-1000511 affects WP ULike versions 2.8.1 and 3.1.