CVE-2025-22787
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 15, 2025
CWE ID 862
Summary
CVE-2025-22787 is a Missing Authorization vulnerability affecting Button Block, a plugin developed by bPlugins LLC. The flaw allows unauthorized access to functionality that is not properly constrained by Access Control Lists (ACLs). This issue impacts Button Block versions from n/a to 1.1.5. Attackers can exploit this vulnerability to gain unwarranted privileges, potentially leading to data breaches or unauthorized modifications to the system. Users are urged to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.