Input validation vulnerability in WordPress Button Plugin MaxButtons 9.7.4

The MaxButtons plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting (XSS). This type of attack can happen when an attacker, who has administrator-level access, injects malicious code into a page. This code can then be executed whenever a user accesses the page. This vulnerability affects multi-site installations and installations where certain security features have been disabled. If an administrator has given button creation privileges to users with lower levels, those users could potentially carry out the attack.

Detected in:

MaxButtons – Create buttons fixed vulnerable versions:
WordPress Button Plugin MaxButtons fixed vulnerable versions: >= * <= 9.7.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.