CVE-2025-22787: WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability
Published Jan 15, 2025
·Updated
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
Affected Software
3 affected components
bPlugins Button Block Wordpress<1.1.6
bPlugins Button Block<=1.1.5
WordPress Button Block<=1.1.5
Remediation
Information
Update the WordPress Button Block wordpress plugin to the latest available version (at least 1.1.6).
Event History
Jan 15, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22787?
CVE-2025-22787 has a medium severity rating due to its impact on access control.
2
How do I fix CVE-2025-22787?
To fix CVE-2025-22787, update the Button Block plugin to version 1.1.6 or later.
3
What are the affected versions for CVE-2025-22787?
CVE-2025-22787 affects bPlugins Button Block and WordPress Button Block versions up to 1.1.5.
4
What type of vulnerability is CVE-2025-22787?
CVE-2025-22787 is a Missing Authorization vulnerability related to improper access control.
5
Who is affected by CVE-2025-22787?
Users of the Button Block plugin from bPlugins LLC and WordPress running versions up to 1.1.5 are affected by CVE-2025-22787.