CVE-2025-8152 affects the WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress, specifically versions up to and including 1.7.0. This vulnerability, a missing capability check (CWE-862), allows unauthenticated attackers to modify data by updating the status of a sticky CTA and changing its displayed name in the backend dashboard. Rated 5.3 MEDIUM on CVSS, it has a low impact on integrity and requires no user interaction or privileges, making it easily exploitable over the network. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Blendmedia | WP CTA – Call Now Button, Sticky Button & Call To Action Builder | >= 0, <= 1.7.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.