← WordPress Vulnerabilities
WordPress security by component

Bread & Butter: AI-Powered Lead Intelligence

Bread & Butter: AI-Powered Lead Intelligence is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 22, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: bread-butter

CVE-2026-4279: Bread & Butter: AI-Powered Lead Intelligence: Cross-site scripting

Bread & Butter: AI-Powered Lead Intelligence is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 8.2.0.25.

PublishedApr 22, 2026
Known safe version> 8.2.0.25
Safe version
Apr 22, 2026 CVE-2026-4279
Bread & Butter: AI-Powered Lead Intelligence: Cross-site scripting
Bread & Butter: AI-Powered Lead Intelligence is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 8.2.0.25.
> 8.2.0.25
CVE6.4
NVDPending
Dec 05, 2025 CVE-2025-12189
Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents: Code execution
Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE4.3
NVD8.8
Nov 19, 2024 CVE-2024-51802
Bread & Butter: Cross-site scripting
Bread & Butter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending