CVE Database /
CVE-2025-11587
CVE · Medium
CVE-2025-11587 — Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11587
|
Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.4 |
Missing Authorization |
Medium
4.3
|
< 1.5.4
|
1.5.4 |
2025-10-28 |
—
|
CVE-2025-11587
The Call Now Button plugin for WordPress, up to version 1.5.3, is susceptible to unauthorized data modification because it lacks proper capability checks in its activation function. Authenticated users with at least Subscriber-level access can exploit this to link their nowbuttons.com account and insert malicious buttons on the site. This vulnerability affects fresh installs that have not been previously set up with an API key.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings