callnowbutton CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

callnowbutton vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to callnowbutton, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-2908 The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). [email protected] 4.3 2.89% 2024-04-26 2025-05-08
CVE-2022-1455 The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled [email protected] 6.1 0.20% 2022-05-16 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence