Bread & Butter: Content Gating for Verified Leads Security & Risk Analysis

wordpress.org/plugins/bread-butter

Turn anonymous traffic into revenue. Get verified leads from your existing forms - no changes required. Automatically enrich user profiles with real j …

40 active installs v8.5.0.100 PHP 7.0.0+ WP 1.0+ Updated Mar 10, 2026
ai-marketingcontent-gatinglead-capturelead-enrichmentlead-generation
98
A · Safe
CVEs total2
Unpatched0
Last CVEDec 4, 2025
Safety Verdict

Is Bread & Butter: Content Gating for Verified Leads Safe to Use in 2026?

Generally Safe

Score 98/100

Bread & Butter: Content Gating for Verified Leads has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 4, 2025Updated 24d ago
Risk Assessment

The 'bread-butter' plugin version 8.5.0.100 exhibits a generally good security posture based on the static analysis. The absence of any unprotected entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the direct attack surface. The plugin also demonstrates good practices in SQL query handling, with 100% of queries using prepared statements, and a high percentage (92%) of output being properly escaped, which mitigates common cross-site scripting vulnerabilities. The presence of nonce and capability checks further strengthens its defenses. However, the static analysis did reveal a concerning number of flows with unsanitized paths (28 out of 32), although thankfully none were classified as critical or high severity. This indicates a potential for vulnerabilities if user input is not rigorously validated before being used in file operations or other sensitive functions.

The vulnerability history of the plugin is a significant concern. With two known medium-severity CVEs, specifically Cross-Site Request Forgery and Cross-site Scripting, it suggests a recurring pattern of insecure coding practices that have previously led to exploitable vulnerabilities. While there are currently no unpatched CVEs, the existence of past vulnerabilities of these types, coupled with the unsanitized path flows in the static analysis, warrants caution. The plugin's strengths lie in its controlled entry points and proper SQL/output handling, but the past vulnerability record and the identified unsanitized path flows are weaknesses that cannot be overlooked, suggesting a need for more comprehensive input sanitization and ongoing security audits.

Key Concerns

  • 2 known medium CVEs
  • 28 flows with unsanitized paths
  • Bundled library (Select2) may be outdated
Vulnerabilities
2

Bread & Butter: Content Gating for Verified Leads Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-12189medium · 4.3Cross-Site Request Forgery (CSRF)

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload

Dec 4, 2025 Patched in 8.0.1398 (5d)
CVE-2024-51802medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lead capture, gated content & newsletter opt-ins <= 7.4.857 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 7.5.880 (29d)
Code Analysis
Analyzed Mar 16, 2026

Bread & Butter: Content Gating for Verified Leads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
62
762 escaped
Nonce Checks
4
Capability Checks
4
File Operations
14
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared1 total queries

Output Escaping

92% escaped824 total outputs
Data Flows
28 unsanitized

Data Flow Analysis

25 flows28 with unsanitized paths
createAdminUser (src\Base\Ajax.php:257)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bread & Butter: Content Gating for Verified Leads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
actioninitbreadbutter-connect.php:34
actionadmin_menusrc\Api\SettingsApi.php:23
actionadmin_initsrc\Api\SettingsApi.php:27
actioninitsrc\Api\SettingsApi.php:39
actionupdated_optionsrc\Api\SettingsApi.php:42
actionrest_api_initsrc\Api\SettingsApi.php:151
actioninitsrc\Base\Ajax.php:79
actionwp_enqueue_scriptssrc\Base\ContactUs.php:13
filterscript_loader_tagsrc\Base\Enqueue.php:17
actionwp_headsrc\Base\Enqueue.php:18
actionwp_enqueue_scriptssrc\Base\Enqueue.php:19
actionwp_enqueue_scriptssrc\Base\Enqueue.php:20
actionadmin_enqueue_scriptssrc\Base\Enqueue.php:21
actionlogin_enqueue_scriptssrc\Base\Enqueue.php:22
filterwp_nav_menu_objectssrc\Base\Enqueue.php:23
actionafter_setup_themesrc\Base\Enqueue.php:24
actionadmin_initsrc\Base\Enqueue.php:25
actionadmin_noticessrc\Base\Enqueue.php:26
filtershow_admin_barsrc\Base\Enqueue.php:46
actionwp_footersrc\Base\Enqueue.php:69
filterthe_contentsrc\Base\GatingContent.php:16
filterpre_get_postssrc\Base\GatingContent.php:17
actionwp_enqueue_scriptssrc\Base\GatingContent.php:18
actionwp_enqueue_scriptssrc\Base\Newsletter.php:13
actioninitsrc\Base\Session.php:12
actionwp_logoutsrc\Base\Session.php:13
actioninitsrc\Base\Shortcode.php:43
actionadmin_initsrc\Pages\Admin.php:75
actionenqueue_block_editor_assetssrc\Pages\Block.php:29
actionlogin_formsrc\Pages\LoginForm.php:15
actionregister_formsrc\Pages\LoginForm.php:16
actionlogin_formsrc\Pages\LoginForm.php:17
actionregister_formsrc\Pages\LoginForm.php:18
Maintenance & Trust

Bread & Butter: Content Gating for Verified Leads Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.0.0
Downloads6K

Community Trust

Rating94/100
Number of ratings7
Active installs40
Developer Profile

Bread & Butter: Content Gating for Verified Leads Developer Profile

Bread & Butter

1 plugin · 40 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
17 days
View full developer profile
Detection Fingerprints

How We Detect Bread & Butter: Content Gating for Verified Leads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bread-butter/src/assets/css/breadbutter-contactus.css/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.js
Script Paths
/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.js
Version Parameters
breadbutter-contactus.css?ver=breadbutter-contactus.js?ver=

HTML / DOM Fingerprints

JS Globals
BB_POST_CONTACTUSBB_CONTACTUS_OVERRIDE_REG_DESTINATION_URLBB_POST_CONTACTUS_DATA
FAQ

Frequently Asked Questions about Bread & Butter: Content Gating for Verified Leads