CVE · Medium

CVE-2017-2169 — MaxButtons – Create buttons [maxbuttons] < 6.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-2169 MaxButtons – Create buttons [maxbuttons] < 6.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.19 6.19 2017-05-16

CVE-2017-2169

The MaxButtons plugin for WordPress, versions prior to 6.19, contains a cross-site scripting flaw that allows attackers to inject malicious scripts. This vulnerability was identified by ASAI Ken and Chris Liu and reported through IPA, with JPCERT/CC facilitating coordination between the researchers and the plugin's developers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.