CVE Database /
CVE-2025-24713
CVE · Medium
CVE-2025-24713 — Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 3.1.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-24713
|
Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 3.1.2 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 3.1.2
|
3.1.2 |
2025-01-24 |
—
|
CVE-2025-24713
The Button Generator - easily Button Builder plugin for WordPress contains a security flaw in versions up to 3.1.1, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities through manipulated requests that deceive administrators into executing unintended actions. This issue arises from inadequate validation of nonces within the affected function, enabling unauthorized access to site functions without proper authentication.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings