CVE-2024-3471: Wow-Company Button Generator

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

Affected products

  • Wow-Company Button Generator: before 3.0 (fixed in 3.0)

Published 2024-05-02. Last modified 2026-06-17.