PT-2025-44275 · WordPress · Call Now Button
Burak Kılınç
·
Published
2025-10-29
·
Updated
2025-10-29
·
CVE-2025-11632
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Call Now Button versions prior to 1.5.5
Description
The Call Now Button plugin for WordPress is susceptible to unauthorized data access because of a missing capability check in multiple functions. Attackers with Subscriber-level access or higher can generate links to a billing portal, allowing them to view and modify billing information, generate chat session tokens, and view domain status. The issue was partially addressed in version 1.5.4 and fully resolved in version 1.5.5. The vulnerable functions lack proper authorization controls, potentially exposing sensitive data.
Recommendations
Update Call Now Button to version 1.5.5 or later.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Call Now Button