CVE-2024-3026

CVE-2024-3026: WordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS

Vendor Unknown
Product WordPress Button Plugin MaxButtons
Published July 13, 2024
Last update August 1, 2024

CVSS base score

—

What the vulnerability does

01Description

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

Key dates

02Disclosure timeline

July 13, 2024 CVE published
August 1, 2024 Record updated