SQL Injection Vulnerability in Like Button Rating Plugin by WordPress
CVE-2026-78285

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2026

What is CVE-2026-78285?

The Like Button Rating Plugin, when used on WordPress sites in versions 2.6.61 and earlier, contains an SQL Injection vulnerability that could allow attackers to manipulate database queries. This flaw may lead to unauthorized access and potential data breaches, highlighting the importance of upgrading to secure versions to protect user data and website integrity.

Affected Version(s)

Like Button Rating <= 2.6.61

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.