CVE-2025-22815: WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Button Block button-block allows Stored XSS.This issue affects Button Block: from n/a through <= 1.1.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22815?
CVE-2025-22815 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-22815?
To fix CVE-2025-22815, update the Button Block plugin to version 1.1.7 or later, which addresses the vulnerability.
Which versions of Button Block are affected by CVE-2025-22815?
CVE-2025-22815 affects Button Block versions from n/a up to and including 1.1.6.
What type of vulnerability is identified in CVE-2025-22815?
CVE-2025-22815 identifies a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Who is the vendor associated with CVE-2025-22815?
The vendor associated with CVE-2025-22815 is bPlugins LLC, the creator of the Button Block plugin.