Callnowbutton
Callnowbutton Call NOW Button: vulnerabilities and CVEs
Callnowbutton Call NOW Button has 5 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11632 | Medium (4.3) | 0.27% | — | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and… |
| CVE-2025-11587 | Medium (4.3) | 0.23% | — | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to,… |
| CVE-2025-24738 | Medium (4.3) | 0.22% | — | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jerry Rietveld Call Now Button call-now-button allows Cross Site Request Forgery.This issue affects Call Now Button: from n/a through <= 1.4.13. |
| CVE-2024-2908 | Medium (4.3) | 0.67% | — | Apr 26, 2024 | The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2022-1455 | Medium (6.1) | 0.79% | — | May 16, 2022 | The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled |