Medium 5.9
2025-04-17< 9.8.4
CVE-2025-39444
Minimum safe version
9.8.4
Update to 9.8.4 or later to address 15 fixable vulnerabilities
CVE-2025-39444
WordPress Button Plugin MaxButtons <= 9.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Text Color
CVE-2024-10555
WordPress MaxButtons Plugin <= 9.7.8 is vulnerable to Sensitive Data Exposure
WordPress MaxButtons Plugin < 9.7.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-7029
CVE-2023-6594
CVE-2014-125092
CVE-2023-36503
MaxButtons 1.19.0 - includes/maxbuttons-button-css.php Authentication Bypass
CVE-2022-38703
CVE-2022-36346
WordPress MaxButtons Plugin <= 1.19.0 - BYPASS
CVE-2014-7181
CVE-2017-2169