CVE-2021-24379
Estado: ModificadaMedia (5.3)—
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.98%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-24379",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "Comments Like Dislike",
"versions": [
{
"status": "affected",
"version": "1.1.4",
"lessThan": "1.1.4",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-06-21T20:15:09.257",
"references": [
{
"url": "https://wpscan.com/vulnerability/aae7a889-195c-45a3-bbe4-e6d4cd2d7fd9",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/aae7a889-195c-45a3-bbe4-e6d4cd2d7fd9",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side"
},
{
"lang": "es",
"value": "El plugin Comments Like Dislike de WordPress versiones anteriores a 1.1.4, permite a usuarios dar me gusta/no me gusta a los comentarios publicados, sin embargo no previene que se repita la petición AJAX para añadir un like. Esto permite a cualquier usuario (incluso no autentificado) añadir un like/dislike ilimitado a cualquier comentario. El plugin parece tener algunos modos de restricción, como la Restricción de Cookies, restricciones de IP, Restricción de Usuarios Registrados, sin embargo, no previenen este ataque ya que sólo comprueban el lado del cliente"
}
],
"lastModified": "2026-06-17T03:39:55.783",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wphappycoders:comments_like_dislike:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "E413D7A1-1C54-4B8D-BEA9-93DE9D5D2E3E",
"versionEndExcluding": "1.1.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}