CVE · Medium

CVE-2025-11587 — Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11587 Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.4 Missing Authorization Medium 4.3 < 1.5.4 1.5.4 2025-10-28

CVE-2025-11587

The Call Now Button plugin for WordPress, up to version 1.5.3, is susceptible to unauthorized data modification because it lacks proper capability checks in its activation function. Authenticated users with at least Subscriber-level access can exploit this to link their nowbuttons.com account and insert malicious buttons on the site. This vulnerability affects fresh installs that have not been previously set up with an API key.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.