WordPress Button Plugin MaxButtons plugin <= 9.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated admin+ can inject persistent scripts via the MaxButtons button editor, affecting versions up to 9.2.
Vulnerability
An authenticated Stored Cross-Site Scripting (XSS) vulnerability exists in the Max Foundry MaxButtons WordPress plugin. Versions up to and including 9.2 fail to properly sanitize user-supplied input in the button editor, allowing users with Administrator-level permissions to inject arbitrary JavaScript. The injected payload is stored and executed in the browsers of other users who view the affected button elements. [2]
Exploitation
An attacker must have an Administrator account (or equivalent role) on the WordPress site to leverage this vulnerability. By creating or editing a button, the attacker can insert malicious scripts into input fields that are not sanitized. Once the button is saved and rendered on a page, any visitor triggers the stored script. No additional user interaction beyond viewing the page is required. [2]
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking, defacement, redirection to malicious sites, or exfiltration of sensitive data. The attack is persistent, meaning the payload executes automatically for every visitor who encounters the compromised button. [2]
Mitigation
The vulnerability is fixed in MaxButtons version 9.3 or later. Users are strongly advised to update to the latest version (9.8.5 as of September 2025) via the WordPress plugin repository. [1] If immediate updating is not possible, users should restrict administrator access to trusted individuals only. No workaround other than removing the plugin or patching is available.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Max Foundry/WordPress Button Plugin MaxButtons (WordPress plugin)v5Range: <= 9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.