VYPR
Unrated severityNVD Advisory· Published Aug 22, 2022· Updated Apr 28, 2026

WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities

CVE-2022-36346

Description

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

MaxButtons WordPress plugin <= 9.2 is vulnerable to multiple CSRF attacks allowing unauthorized actions by tricking logged-in admins.

Vulnerability

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities exist in the MaxButtons plugin for WordPress, version 9.2 and earlier [1]. These flaws allow an attacker to trick an authenticated administrator into performing unintended actions, such as modifying button settings or deleting buttons, without their knowledge.

Exploitation

To exploit the vulnerability, an attacker must convince a logged-in WordPress administrator to click a crafted link or visit a malicious webpage while authenticated to the admin panel [1]. No additional privileges are required beyond the victim having an active session. The attacker can then force the victim to unknowingly execute arbitrary actions within the MaxButtons plugin.

Impact

Successful exploitation enables an attacker to perform arbitrary actions on behalf of the victim administrator, including creating, editing, or deleting buttons and potentially changing plugin settings [1]. This could lead to website defacement, data loss, or further compromise of the WordPress installation.

Mitigation

The vulnerabilities are fixed in version 9.3 or later [1]. The current latest version (9.8.5) is not affected. Administrators should update the plugin to the latest available version. No workarounds have been disclosed.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.