Access violation vulnerability in Call Now Button – The #1 Click to Call Button for WordPress 1.5.3

The Call Now Button is a popular plugin for WordPress websites that allows visitors to call the site owner with just one click. However, it has a vulnerability that could allow unauthorized changes to be made to the plugin’s data. This means that someone with access to the site, such as a Subscriber or higher, could connect the plugin to their own account and add harmful call buttons to the site. This vulnerability can only be exploited on new installations where the plugin has not yet been set up with an API key.

Detected in:

Call Now Button – The #1 Click to Call Button for WordPress fixed vulnerable versions: >= * <= 1.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.