CVE-2026-78285: WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability
Published Aug 27, 2026
·Updated
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Affected Software
1 affected component
WordPress Like Button Rating plugin<=2.6.61
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Like Button Rating pluginto a version that resolves this vulnerability.Fixed in 2.6.62
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs a low-privileged authenticated account, such as a Subscriber. Exploitation is network-accessible, requires low complexity, and does not require user interaction.
2
What is the likely security impact if exploitation succeeds?
The vulnerability can expose highly sensitive information and has a low availability impact. The supplied vector indicates no integrity impact, but the impact scope may extend beyond the vulnerable component.