Description
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
Published: 2025-01-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Missing Authorization flaw, which allows users to access functionality that is not properly protected by access controls. Affected code paths can be reached without verifying the caller’s permissions, enabling unauthorized use of the plugin’s administrative features. The weakness corresponds to CWE-862, and while it does not allow arbitrary code execution, it can lead to data tampering, configuration changes, or other unintended actions within the WordPress site.

Affected Systems

bPlugins Button Block, a WordPress plugin, is impacted for all releases up to and including version 1.1.5. The issue applies across all operating systems and installations that use any of the affected releases; no specific OS or deployment details are provided.

Risk and Exploitability

The CVSS score for this issue is 4.3, indicating low severity. EPSS indicates an exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack surface is likely an authenticated or unauthenticated user who can craft requests to the plugin’s endpoints; because the lack of authorization is not limited to a particular phase, automated exploitation scripts could be built if the plugin is publicly accessible. However, the low EPSS score suggests attackers may not prioritize this flaw in the current threat landscape.

Generated by OpenCVE AI on May 2, 2026 at 06:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Button Block plugin to the latest available version, which removes the broken access controls.
  • If an upgrade is not immediately possible, disable or remove the Button Block plugin to eliminate the vulnerable code path.
  • Configure web application firewall or access control rules to restrict remote access to the plugin’s endpoints until a patch is applied.

Generated by OpenCVE AI on May 2, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2996 Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5. Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 25 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Bplugins
Bplugins button Block
CPEs cpe:2.3:a:bplugins:button_block:*:*:*:*:*:wordpress:*:*
Vendors & Products Bplugins
Bplugins button Block

Wed, 15 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5.
Title WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Bplugins Button Block
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:07.237Z

Reserved: 2025-01-07T21:05:06.989Z

Link: CVE-2025-22787

cve-icon Vulnrichment

Updated: 2025-01-15T19:27:59.689Z

cve-icon NVD

Status : Modified

Published: 2025-01-15T16:15:41.603

Modified: 2026-04-23T15:23:36.953

Link: CVE-2025-22787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses