Input validation vulnerability in WordPress Button Plugin MaxButtons 9.2

The WordPress Button Plugin MaxButtons has a vulnerability that allows attackers with contributor-level permissions or higher to insert malicious web scripts into pages. This malicious code will be executed when a user visits the page. This vulnerability exists in all versions up to and including 9.2 due to the plugin not properly checking user input and not providing enough protection for the output.

Detected in:

MaxButtons – Create buttons fixed vulnerable versions:
WordPress Button Plugin MaxButtons fixed vulnerable versions: >= * <= 9.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.