Description
Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.
Published: 2025-02-26
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the Required Admin Menu Manager plugin enables an attacker to force an authenticated WordPress user to execute actions hosted by the plugin. Based on the description, it is inferred that the attacker needs a victim with an active authenticated WordPress session to exploit this flaw. Because the flaw allows the attacker to submit forged requests that are accepted by the plugin without prompting the user, unintended menu configurations or other administrative changes can be made. The sole weakness underlying the issue is a missing protection against CSRF, identified as CWE‑352.

Affected Systems

All releases of the WordPress Admin Menu Manager plugin up to and including 1.0.3 are vulnerable. Users running any version 1.0.3 or earlier should consider those installations affected.

Risk and Exploitability

The vulnerability’s CVSS score of 4.3 indicates a moderate risk level. EPSS indicates a very low probability of exploitation in the wild; the issue is not presently listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires an authenticated WordPress session, meaning the attacker typically needs to entice the victim to click a malicious link or send a forged request from a compromised domain. Once the authenticated session is tricked, the attacker can change menu settings or otherwise alter the plugin’s configuration.

Generated by OpenCVE AI on May 2, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Admin Menu Manager to version 1.0.4 or later, which resolves the CSRF issue.
  • If an upgrade is not immediately possible, disable the plugin or remove it until a patch is applied.
  • Enable site‑wide CSRF protection or apply a Web Application Firewall to detect and block forged requests targeting the plugin’s endpoints.

Generated by OpenCVE AI on May 2, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5343 Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager admin-menu-manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through <= 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager admin-menu-manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through <= 1.0.3.
References

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 13:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.
Title WordPress Admin Menu Manager plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:44.155Z

Reserved: 2025-02-17T11:51:01.644Z

Link: CVE-2025-26925

cve-icon Vulnrichment

Updated: 2025-02-26T14:28:35.371Z

cve-icon NVD

Status : Deferred

Published: 2025-02-26T14:15:11.743

Modified: 2026-04-28T19:29:49.530

Link: CVE-2025-26925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:15:06Z

Weaknesses