Skip to content
Noroxi

MaxButtons – Create buttons

maxbuttons · plugin

Known security vulnerabilities for MaxButtons – Create buttons. Find out in seconds which version runs on your site with WP Lens.

10 known vulnerabilities

4 exploitable without logging in · latest Jun 27, 2026

Listed on wordpress.org · latest 9.8.6 · last updated Sep 30, 2026 · 70K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2022-36346unauthenticated · needs a click≤ 9.2

    WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities

    High 8.8
  • CVE-2026-13245unauthenticated · needs a click≤ 9.8.5

    MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter

    Medium 6.1
  • CVE-2017-2169unauthenticated · needs a click

    Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows remote attackers to i

    Medium 6.1
  • CVE-2025-39444high privilege≤ 9.8.3

    WordPress MaxButtons plugin <= 9.8.3 - Cross Site Scripting (XSS) vulnerability

    Medium 5.9
  • CVE-2023-7029contributor+≤ 9.7.6

    WordPress Button Plugin MaxButtons <= 9.7.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

    Medium 5.4
  • CVE-2023-36503contributor+≤ 9.5.3

    WordPress MaxButtons Plugin <= 9.5.3 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2024-6499unauthenticated≤ 9.7.8

    WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure

    Medium 5.3
  • CVE-2023-6594admin≤ 9.7.4

    WordPress Button Plugin MaxButtons <= 9.7.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Medium 4.8
  • CVE-2022-38703admin≤ 9.2

    WordPress Button Plugin MaxButtons plugin <= 9.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

    Medium 4.8
  • CVE-2014-7181

    Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory