MaxButtons – Create buttons
maxbuttons · plugin
Known security vulnerabilities for MaxButtons – Create buttons. Find out in seconds which version runs on your site with WP Lens.
10 known vulnerabilities
4 exploitable without logging in · latest Jun 27, 2026
Listed on wordpress.org · latest 9.8.6 · last updated Sep 30, 2026 · 70K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 8.8
CVE-2022-36346unauthenticated · needs a click≤ 9.2
WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
- Medium 6.1
CVE-2026-13245unauthenticated · needs a click≤ 9.8.5
MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter
- Medium 6.1
CVE-2017-2169unauthenticated · needs a click
Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows remote attackers to i
- Medium 5.9
CVE-2025-39444high privilege≤ 9.8.3
WordPress MaxButtons plugin <= 9.8.3 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2023-7029contributor+≤ 9.7.6
WordPress Button Plugin MaxButtons <= 9.7.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
- Medium 5.4
CVE-2023-36503contributor+≤ 9.5.3
WordPress MaxButtons Plugin <= 9.5.3 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.3
CVE-2024-6499unauthenticated≤ 9.7.8
WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure
- Medium 4.8
CVE-2023-6594admin≤ 9.7.4
WordPress Button Plugin MaxButtons <= 9.7.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Medium 4.8
CVE-2022-38703admin≤ 9.2
WordPress Button Plugin MaxButtons plugin <= 9.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).