← WordPress Vulnerabilities
WordPress security by component

MaxButtons – Create buttons

MaxButtons – Create buttons is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Jun 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: maxbuttons

CVE-2026-13245: MaxButtons – Create buttons: Cross-site scripting

MaxButtons – Create buttons is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.8.5.

PublishedJun 27, 2026
Known safe version> 9.8.5
Safe version
Jun 27, 2026 CVE-2026-13245
MaxButtons – Create buttons: Cross-site scripting
MaxButtons – Create buttons is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.8.5.
> 9.8.5
CVE6.1
NVDPending
Apr 17, 2025 CVE-2025-39444
MaxButtons: Cross-site scripting
MaxButtons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Dec 20, 2024 CVE-2024-8968
WordPress Button Plugin MaxButtons: Cross-site scripting
WordPress Button Plugin MaxButtons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVDPending
Dec 20, 2024 CVE-2024-10555
WordPress Button Plugin MaxButtons: Cross-site scripting
WordPress Button Plugin MaxButtons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Aug 24, 2024 CVE-2024-6499
WordPress Button Plugin MaxButtons: A security weakness
WordPress Button Plugin MaxButtons is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jul 13, 2024 CVE-2024-3026
WordPress Button Plugin MaxButtons: Cross-site scripting
WordPress Button Plugin MaxButtons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Feb 05, 2024 CVE-2023-7029
WordPress Button Plugin MaxButtons: Cross-site scripting
WordPress Button Plugin MaxButtons is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 09, 2024 CVE-2023-6594
WordPress Button Plugin MaxButtons: Cross-site scripting
WordPress Button Plugin MaxButtons is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jul 25, 2023 CVE-2023-36503
Maxbuttons: Cross-site scripting
Maxbuttons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 05, 2023 CVE-2014-125092
Maxbuttons: Cross-site scripting
Maxbuttons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD6.1
Sep 23, 2022 CVE-2022-38703
Maxbuttons: Cross-site scripting
Maxbuttons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.4
NVD4.8
Aug 22, 2022 CVE-2022-36346
Maxbuttons: Cross-site request forgery
Maxbuttons is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
May 22, 2017 CVE-2017-2169
Maxbuttons: Cross-site scripting
Maxbuttons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 16, 2014 CVE-2014-7181
Maxbuttons: Cross-site scripting
Maxbuttons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3