CVE Database /
CVE-2023-25443
CVE · Medium
CVE-2023-25443 — Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-25443
|
Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.6 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 2.3.6
|
2.3.6 |
2023-05-25 |
—
|
CVE-2023-25443
The Button Generator plugin versions before 2.3.6 contain a cross-site request forgery flaw that was discovered by Rio Darmawan. An attacker could exploit this vulnerability to trick authenticated users with higher privilege levels into performing unintended actions while logged in. No patched version has been released, and the WordPress plugin review team was informed of the issue in February 2023.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings