CVE Database /
CVE-2025-11632
CVE · Medium
CVE-2025-11632 — Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11632
|
Call Now Button – The #1 Click to Call Button for WordPress [call-now-button] < 1.5.5 |
Missing Authorization |
Medium
4.3
|
< 1.5.5
|
1.5.5 |
2025-10-29 |
—
|
CVE-2025-11632
A security flaw exists within the Call Now Button plugin for WordPress, allowing authenticated users with a Subscriber-level access or higher to bypass certain checks on multiple functions. As a result, these individuals can potentially access sensitive information such as billing details and domain status, and even manipulate connected accounts by generating unauthorized chat session tokens. The vulnerability was initially addressed in version 1.5.4 but fully resolved in the subsequent release, version 1.5.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings