PLUGIN SECURITY
Is WP ULike safe?
One-click like buttons your visitors actually use, plus a built-in analytics dashboard that shows what your audience loves. No vote limits.
What this plugin does
- Slug:
wp-ulike - Author: Alimir
- 60000+ active installs
- 96/100 rating (281 reviews on wordpress.org)
- 2580385 all-time downloads
- On WordPress.org since 2014-08-28
engagement analyticslike buttonpopular postspost reactionsvoting
Maintenance status
- Last updated: 2026-08-07 7:39am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.3.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
15 known CVEs on file for WP ULike.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-32259 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.10 | Missing Authorization | Medium 5.3 | < 4.7.10 | 4.7.10 | 2025-04-04 | — |
| CVE-2024-12770 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.7.6 | 4.7.6 | 2025-01-23 | — |
| CVE-2025-22738 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 4.7.7 | 4.7.7 | 2025-01-14 | — |
| CVE-2024-9649 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 4.7.5 | 4.7.5 | 2024-10-15 | — |
| CVE-2024-7879 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.7.5 | 4.7.5 | 2024-10-15 | — |
| CVE-2024-7878 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.7.4 | 4.7.4 | 2024-09-04 | — |
| CVE-2024-6792 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.2.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Low 3.5 | < 4.7.2.1 | 4.7.2.1 | 2024-08-16 | — |
| CVE-2024-6094 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.7.1 | 4.7.1 | 2024-07-03 | — |
+ 11 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-1759 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.7.0 | 4.7.0 | 2024-04-26 | — |
| CVE-2024-1572 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.7.0 | 4.7.0 | 2024-04-26 | — |
| CVE-2024-1797 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.7.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 4.7.0 | 4.7.0 | 2024-04-26 | — |
| CVE-2023-45640 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.6.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 4.6.9 | 4.6.9 | 2023-10-12 | — |
| CVE-2022-45842 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 4.6.5 | Time-of-check Time-of-use (TOCTOU) Race Condition | Medium 5.3 | < 4.6.5 | 4.6.5 | 2022-11-24 | — |
| — | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 3.2 | — | Unknown | < 3.2 | 3.2 | 2018-06-05 | — |
| CVE-2018-1000508 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 3.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2 | 3.2 | 2018-05-14 | — |
| CVE-2018-1000511 | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 3.2 | Incorrect Permission Assignment for Critical Resource | High 7.5 | < 3.2 | 3.2 | 2018-05-14 | — |
| — | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 5.0.0 | — | Medium 5.3 | < 5.0.0 | 5.0.0 | 0000-00-00 | — |
| — | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 5.0.2 | — | Unknown | < 5.0.2 | 5.0.2 | 0000-00-00 | — |
| — | WP ULike – Like Buttons, Voting & Engagement Analytics [wp-ulike] < 3.2 | — | Unknown | < 3.2 | 3.2 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Easy Social Like Box – Popup – Sidebar Widget — 7000+ active installs — 88/100 (18) — max PHP 8.4
- Like Button Rating ♥ LikeBtn — 4000+ active installs — 88/100 (273) — max PHP 8.4
- Profile Box Shortcode And Widget — 1000+ active installs — 74/100 (7) — max PHP 8.4
- All-in-one Like Widget — 1000+ active installs — 98/100 (7)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.