Stored Cross-Site Scripting Vulnerability in MaxButtons Plugin for WordPress
CVE-2023-6594
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 January 2024
What is CVE-2023-6594?
The MaxButtons plugin for WordPress allows an authenticated user with administrator-level permissions to inject malicious web scripts through its admin settings. This vulnerability arises from insufficient input sanitization and output escaping, impacting all versions up to and including 9.7.4. It primarily affects multi-site installations and those where unfiltered_html has been disabled. Consequently, users with lower privileges, such as contributors, could gain button creation rights, further facilitating potential XSS attacks against unsuspecting users. Proper security measures and updates are essential to mitigate these risks.
Affected Version(s)
WordPress Button Plugin MaxButtons * <= 9.7.4