CVE · Medium

CVE-2025-24713 — Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 3.1.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24713 Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 3.1.2 Cross-Site Request Forgery (CSRF) Medium 5.4 < 3.1.2 3.1.2 2025-01-24

CVE-2025-24713

The Button Generator - easily Button Builder plugin for WordPress contains a security flaw in versions up to 3.1.1, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities through manipulated requests that deceive administrators into executing unintended actions. This issue arises from inadequate validation of nonces within the affected function, enabling unauthorized access to site functions without proper authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.