Stored Cross-Site Scripting Vulnerability in MaxButtons Plugin for WordPress
CVE-2023-6594
4.8MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 January 2024
Summary
The MaxButtons plugin for WordPress allows an authenticated user with administrator-level permissions to inject malicious web scripts through its admin settings. This vulnerability arises from insufficient input sanitization and output escaping, impacting all versions up to and including 9.7.4. It primarily affects multi-site installations and those where unfiltered_html has been disabled. Consequently, users with lower privileges, such as contributors, could gain button creation rights, further facilitating potential XSS attacks against unsuspecting users. Proper security measures and updates are essential to mitigate these risks.
Affected Version(s)
WordPress Button Plugin MaxButtons * <= 9.7.4
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada