---
id: CVE-2025-11632
title: >-
  The Call Now Button – The #1 Click to Call Button for WordPress plugin for
  WordPress is vulnerable to unauthorized access of data due to a missing
  capability check on multiple functions in all versions up to, and including,
  1.5.4
summary: >-
  The Call Now Button – The #1 Click to Call Button for WordPress plugin for
  WordPress is vulnerable to unauthorized access of data due to a missing
  capability check on multiple functions in all versions up to, and including,
  1.5.4. This m…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
published: '2025-10-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11632'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/CnbAdminAjax.php#L147
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/CnbAdminAjax.php#L154
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/CnbAdminAjax.php#L167
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/CnbAdminAjax.php#L21
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/CnbAdminAjax.php#L50
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/call-now-button/tags/1.5.3/src/admin/chat/class-cnb-chat-controller.php#L52
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/379547a2-6b22-4ec9-8570-a043dda7ec09?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00269
epssPercentile: 0.17521
ingestedAt: '2026-10-08T11:31:27.673Z'
---

## Overview

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate links to billing portal, where they can view and modify billing information of the connected, account, generate chat session tokens, view domain status, etc.
This vulnerability was partially fixed in version 1.5.4 and fully fixed in version 1.5.5

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
