CVE Database /
CVE-2023-49155
CVE · Medium
CVE-2023-49155 — Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-49155
|
Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.9 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 2.3.9
|
2.3.9 |
2023-11-28 |
—
|
CVE-2023-49155
The Button Generator plugin for WordPress up to version 2.3.8 contains a cross-site request forgery vulnerability affecting the btg_count() function, which lacks proper nonce verification. An attacker could craft a malicious request that, when executed by a tricked site administrator, would reset the button counter without authorization. This flaw allows unauthenticated users to perform unwanted actions on the site if they can convince an admin to interact with a specially crafted link.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings