CVE · Medium

CVE-2023-49155 — Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-49155 Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 2.3.9 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.3.9 2.3.9 2023-11-28

CVE-2023-49155

The Button Generator plugin for WordPress up to version 2.3.8 contains a cross-site request forgery vulnerability affecting the btg_count() function, which lacks proper nonce verification. An attacker could craft a malicious request that, when executed by a tricked site administrator, would reset the button counter without authorization. This flaw allows unauthenticated users to perform unwanted actions on the site if they can convince an admin to interact with a specially crafted link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.