Medium severity5.4NVD Advisory· Published Jul 13, 2024· Updated Jun 17, 2026
CVE-2024-3026
CVE-2024-3026
Description
The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<9.7.8+ 1 more
- (no CPE)range: <9.7.8
- (no CPE)range: <9.7.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/aba9d8a5-20a7-49e5-841c-9cfcb9bc6144/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.