Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons maxbuttons allows Stored XSS.This issue affects MaxButtons: from n/a through <= 9.8.3.
Published: 2025-04-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of input during web page generation that allows an attacker to store a malicious script in the MaxButtons plugin data. The stored script can then be executed whenever a page that renders the button is viewed, potentially compromising the browser session of any site visitor. Because the injection is stored in the site's database, the effect persists across users and sessions. The weakness is a classic Cross‑Site Scripting flaw (CWE‑79).

Affected Systems

The MaxButtons WordPress plugin released by Maxfoundry, for versions up through 9.8.3, is affected. Users of any WordPress installation running a version of the plugin that is not newer than 9.8.3 may be vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity, and the EPSS score of less than 1 percent suggests that, as of the latest data, the probability of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog, so no known active exploits are reported. The likely attack requires an attacker to inject a malicious input into the plugin’s interface or storage mechanism—typically by creating or editing a button. Because the data is rendered on public pages, an unauthenticated user who can view the affected page will be subject to the payload. If the plugin restricts creation to privileged users, the risk is confined to those accounts; otherwise, any visitor could be impacted. Given the moderate CVSS and very low EPSS, the overall risk remains moderate but should be mitigated promptly.

Generated by OpenCVE AI on April 30, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MaxButtons plugin to a version newer than 9.8.3, which removes the injection point.
  • If an update is not immediately available, disable or delete the plugin to eliminate the stored‑XSS vector.
  • Inspect existing button configurations for hidden or obfuscated script code and remove any suspicious entries.

Generated by OpenCVE AI on April 30, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11568 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons allows Stored XSS. This issue affects MaxButtons: from n/a through 9.8.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons maxbuttons allows Stored XSS.This issue affects MaxButtons: from n/a through <= 9.8.3.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 14 May 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons allows Stored XSS. This issue affects MaxButtons: from n/a through 9.8.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3.

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons allows Stored XSS. This issue affects MaxButtons: from n/a through 9.8.3.
Title WordPress MaxButtons plugin <= 9.8.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Maxfoundry Maxbuttons
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:31.712Z

Reserved: 2025-04-16T06:23:22.137Z

Link: CVE-2025-39444

cve-icon Vulnrichment

Updated: 2025-04-17T16:01:41.266Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:55.043

Modified: 2026-04-23T15:29:34.487

Link: CVE-2025-39444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:30:02Z

Weaknesses