PT-2014-7819 · Maxbuttons · Maxbuttons

Published

2014-10-16

·

Updated

2018-10-09

·

CVE-2014-7181

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MaxButtons plugin versions prior to 1.26.1
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the "maxbuttons-controller" page to "wp-admin/admin.php", related to the button creation page.
Recommendations For MaxButtons plugin versions prior to 1.26.1, update to version 1.26.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the maxbuttons-controller page in wp-admin/admin.php to minimize the risk of exploitation. Avoid using the id parameter in the affected button action until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7181

Affected Products

Maxbuttons