CVE-2026-13245Disclosure

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-27: 4PoC Mentioned / Linked · 2026-06-27: 1Exploit Tool / Code · 2026-06-27: 1Technical Details · 2026-06-27: 406-27
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-13245 The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.… https://www.cve.org/CVERecord?id=CVE-2026-13245

    Post summary

    The post announces a Reflected XSS flaw in the MaxButtons WordPress plugin via the 'view' parameter, but does not provide a PoC, exploit code, or patch details.

    00020696
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13245 Reflected Cross-Site Scripting in MaxButtons Create Buttons Plugin WordPress 9.8.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13245

    Post summary

    This entry announces CVE-2026-13245, describing a Reflected Cross‑Site Scripting flaw in the MaxButtons Create Buttons Plugin for WordPress 9.8.5, with a reference to a vulnerability details page.

    00020103
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13245 The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.… https://www.cve.org/CVERecord?id=CVE-2026-13245 ----- Traducción: CVE-2026-13245 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-13245, stating the MaxButtons WordPress plugin suffers reflected XSS via the 'view' parameter and links to the CVE record.

    0001032
    89 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-13245-maxbuttons-version-9-8-5-medium-vulnerability-proof-of-concept CVE-2026-13245 maxbuttons (CVSS Score 6.1) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge #cybe…

    Post summary

    A proof‑of‑concept for CVE‑2026‑13245 against MaxButtons v9.8.5 is publicly released with a CVSS score of 6.1; no patches or evidence of active exploitation are mentioned.

    0001051
    11 followersView on X

Explore more