N/A
2026-03-10< 5.0.2
WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute
Minimum safe version
5.0.2
Update to 5.0.2 or later to address 19 fixable vulnerabilities
WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute
WP ULike <= 4.8.3.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter
CVE-2024-12770
CVE-2025-32259
CVE-2025-22738
CVE-2024-7879
CVE-2024-9649
CVE-2024-7878
WordPress WP ULike Plugin < 4.7.2.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-6094
CVE-2024-1797
CVE-2024-1572
CVE-2024-1759
CVE-2023-45640
WP ULike <= 3.1 - Unauthenticated Stored XSS
CVE-2022-45842
WordPress WP ULike plugin <= 3.1 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2018-1000511
CVE-2018-1000508