What the vulnerability does
01Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress
Explanation of Vulnerability in Simple Terms
The MaxButtons WordPress plugin version 9.2 and earlier contains a stored cross-site scripting (XSS) vulnerability. An authenticated admin user with high privileges can inject malicious JavaScript into button configurations. When other users view pages containing these buttons, the injected script executes in their browsers, potentially compromising their sessions or stealing data.
What an attacker can do
Inject malicious JavaScript that runs when site visitors view pages with affected buttons.
Potential impact on your site
Compromised site visitors may have sessions hijacked or credentials stolen if an admin account is compromised.
Conditions required to exploit
Admin-level access to the WordPress site and user interaction (victim must view the affected page).
Key dates
External resources
Related vulnerabilities