Impact
The MaxButtons – Create buttons plugin for WordPress is vulnerable to reflected Cross‑Site Scripting via the unsanitized 'view' parameter. This vulnerability allows unauthenticated attackers to inject arbitrary scripts that will be executed when a victim clicks a crafted link. The weakness arises from insufficient input sanitization and lack of output escaping (CWE‑79).
Affected Systems
WordPress sites running the MaxButtons – Create buttons plugin from maxfoundry, versions earlier.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating a medium severity. EPSS is unavailable, so the probability of exploitation is not quantified, and it is not listed in CISA KEV. The attack requires a malicious link that tricks a user to trigger the vulnerable 'view' parameter, making it a client‑side exploit that depends on user interaction.
OpenCVE Enrichment