First published: Mon Aug 22 2022(Updated: )
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Maxbuttons | <=9.2 |
Update to 9.3 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36346 is categorized as a high severity vulnerability due to its Cross-Site Request Forgery (CSRF) risk.
To fix CVE-2022-36346, update the Max Foundry MaxButtons plugin to version 9.3 or newer.
CVE-2022-36346 includes multiple Cross-Site Request Forgery (CSRF) vulnerabilities affecting versions up to 9.2 of the MaxButtons plugin.
Yes, CVE-2022-36346 can be exploited to perform unauthorized actions on behalf of users without their consent.
CVE-2022-36346 affects all versions of the MaxButtons plugin up to and including version 9.2.