plugin

Call Now Button Vulnerabilities

10 known security issues reported for the Call Now Button WordPress plugin. Most recent disclosed Oct 29, 2025.

5 medium

Running Call Now Button on your site? Check whether your installed version is affected.

Scan your site free

Call Now Button <= 1.5.4 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions

medium

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

CVSS:
4.3
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Oct 29, 2025

CVE-2025-11632 on NVD →

Call Now Button &#8211; The #1 Click to Call Button for WordPress [call-now-button] < 1.5.4

unknown

[en] The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level a...

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Oct 29, 2025

CVE-2025-11587 on NVD →

Call Now Button &#8211; The #1 Click to Call Button for WordPress [call-now-button] < 1.5.5

unknown

[en] The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-level access and...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Oct 29, 2025

CVE-2025-11632 on NVD →

Call Now Button <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Settings Update

medium

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
4.3
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Oct 28, 2025

CVE-2025-11587 on NVD →

Call Now Button <= 1.4.13 - Cross-Site Request Forgery

medium

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unknown ac...

CVSS:
4.3
Affected:
up to 1.4.13
Fixed in:
1.4.14
Disclosed:
Jan 24, 2025

CVE-2025-24738 on NVD →

Call Now Button &#8211; The #1 Click to Call Button for WordPress [call-now-button] < 1.4.14

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in NowButtons.com Call Now Button allows Cross Site Request Forgery. This issue affects Call Now Button: from n/a through 1.4.13.

Affected:
up to 1.4.14
Fixed in:
1.4.14
Disclosed:
Jan 24, 2025

CVE-2025-24738 on NVD →

Call Now Button &#8211; The #1 Click to Call Button for WordPress [call-now-button] < 1.4.7

unknown

[en] The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Apr 26, 2024

CVE-2024-2908 on NVD →

Call Now Button <= 1.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 1.4.6
Fixed in:
1.4.7
Disclosed:
Apr 5, 2024

CVE-2024-2908 on NVD →

Call Now Button &#8211; The #1 Click to Call Button for WordPress [call-now-button] < 1.1.2

unknown

[en] The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
May 16, 2022

CVE-2022-1455 on NVD →

Call Now Button <= 1.1.1 - Reflected Cross-Site Scripting

medium

The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when premium is enabled

CVSS:
6.1
Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Apr 25, 2022

CVE-2022-1455 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database