What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder button-generation allows Cross Site Request Forgery.This issue affects Button Generator – easily Button Builder: from n/a through <= 3.1.1.
Explanation of Vulnerability in Simple Terms
02Summary
Button Generator through version 3.1.1 contains a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of site administrators. An attacker can craft a malicious link or page that, when visited by an authenticated admin, triggers unwanted changes to button settings or configuration. The vulnerability requires user interaction—the admin must click a link or visit a page controlled by the attacker.
What an attacker can do
03Attacker Capabilities
Trick an admin into modifying button settings or configuration without their knowledge.
Potential impact on your site
04Site Impact
Attackers can alter button configurations, potentially defacing the site or redirecting users to malicious destinations.
Conditions required to exploit
05Prerequisites
Admin must click a malicious link or visit an attacker-controlled page while logged in.
Key dates
06Disclosure timeline
January 24, 2025
CVE published
May 12, 2026
Record updated