A vulnerability classified as problematic has been found in maxfoundry MaxButtons Plugin up to 9.8.5 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument view results in cross site scripting.

This vulnerability is reported as CVE-2026-13245. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.