WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
Description
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
MaxButtons WordPress plugin <= 9.2 is vulnerable to multiple CSRF attacks allowing unauthorized actions by tricking logged-in admins.
Vulnerability
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities exist in the MaxButtons plugin for WordPress, version 9.2 and earlier [1]. These flaws allow an attacker to trick an authenticated administrator into performing unintended actions, such as modifying button settings or deleting buttons, without their knowledge.
Exploitation
To exploit the vulnerability, an attacker must convince a logged-in WordPress administrator to click a crafted link or visit a malicious webpage while authenticated to the admin panel [1]. No additional privileges are required beyond the victim having an active session. The attacker can then force the victim to unknowingly execute arbitrary actions within the MaxButtons plugin.
Impact
Successful exploitation enables an attacker to perform arbitrary actions on behalf of the victim administrator, including creating, editing, or deleting buttons and potentially changing plugin settings [1]. This could lead to website defacement, data loss, or further compromise of the WordPress installation.
Mitigation
The vulnerabilities are fixed in version 9.3 or later [1]. The current latest version (9.8.5) is not affected. Administrators should update the plugin to the latest available version. No workarounds have been disclosed.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Max Foundry/MaxButtons (WordPress plugin)v5Range: <= 9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- patchstack.com/database/vulnerability/maxbuttons/wordpress-maxbuttons-plugins-9-2-multiple-cross-site-request-forgery-csrf-vulnerabilitiesmitrex_refsource_CONFIRM
- wordpress.org/plugins/maxbuttons/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.