Junglewise Threat Intelligence

CVE-2026-78285: Like Button Rating SQL injection

CVE-2026-78285 · Severity: high · CVSS 8.5 · Published 2026-08-27

Vendors: Themeisle.

Executive brief

The Like Button Rating WordPress plugin contains a SQL injection vulnerability that allows authenticated subscribers to read, modify, or delete the entire database, including user accounts and sensitive customer data. Exploitation requires subscriber-level access but could lead to complete compromise of a WordPress site's data and user privacy.

Technical details

A SQL injection vulnerability exists in the Like Button Rating WordPress plugin versions 2.6.61 and earlier. The vulnerability requires subscriber-level privileges to exploit but allows an attacker to execute arbitrary SQL queries against the WordPress database. An attacker with subscriber access can read, modify, or delete sensitive data including user accounts, posts, and private information. The vulnerability has been patched in version 2.6.62, and users should update immediately to mitigate the risk.

Affected products

  • ThemeIsle Like Button Rating <= 2.6.61

Timeline

  • 2026-08-25: disclosed: Vulnerability reported to Patchstack
  • 2026-08-27: advisory: CVE-2026-78285 published
  • 2026-08-25: patched: Patch released in version 2.6.62

References