Input validation vulnerability in WordPress Button Plugin MaxButtons 9.5.3

The MaxButtons plugin for WordPress has a security flaw that allows malicious users with contributor-level access or higher to inject malicious web scripts into pages. This could cause these scripts to run when a user views the page, potentially causing harm to the user. This vulnerability is present in versions up to, and including, 9.5.3, due to the plugin’s lack of proper input sanitization and output escaping.

Detected in:

MaxButtons – Create buttons fixed vulnerable versions:
WordPress Button Plugin MaxButtons fixed vulnerable versions: >= * <= 9.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.