CVE · Medium

CVE-2025-11632 — Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11632 Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.5 Missing Authorization Medium 4.3 < 1.5.5 1.5.5 2025-10-29

CVE-2025-11632

A security flaw exists within the Call Now Button plugin for WordPress, allowing authenticated users with a Subscriber-level access or higher to bypass certain checks on multiple functions. As a result, these individuals can potentially access sensitive information such as billing details and domain status, and even manipulate connected accounts by generating unauthorized chat session tokens. The vulnerability was initially addressed in version 1.5.4 but fully resolved in the subsequent release, version 1.5.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.