Description
Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar wp-hide-admin-bar allows Cross Site Request Forgery.This issue affects WP Hide Admin Bar: from n/a through <= 2.0.
Published: 2025-03-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Hide Admin Bar plugin does not validate anti‑CSRF tokens for certain administrative requests. This flaw permits an attacker to construct a link or form that, when visited or submitted by an authenticated WordPress user, sends a request to the plugin’s endpoints without a valid token, potentially changing plugin settings or triggering plugin‑controlled actions.

Affected Systems

Any WordPress site that has installed the WP Hide Admin Bar plugin version 2.0 or earlier, regardless of the WordPress core version.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Typical exploitation would rely on social engineering or a compromised site to host a crafted link or form that the victim visits, resulting in an unauthorized request being processed by the plugin.

Generated by OpenCVE AI on May 2, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Hide Admin Bar plugin to the latest available version or uninstall the plugin to remove the vulnerability.
  • Enable a web application firewall and configure rules to block POST requests to the WP Hide Admin Bar endpoint that lack a valid CSRF token.
  • Review WordPress administrative account privileges and restrict the number of users who can perform plugin edits or activate/deactivate plugins.

Generated by OpenCVE AI on May 2, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7865 Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar allows Cross Site Request Forgery. This issue affects WP Hide Admin Bar: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar allows Cross Site Request Forgery. This issue affects WP Hide Admin Bar: from n/a through 2.0. Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar wp-hide-admin-bar allows Cross Site Request Forgery.This issue affects WP Hide Admin Bar: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00021}

epss

{'score': 0.00029}


Wed, 12 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar allows Cross Site Request Forgery. This issue affects WP Hide Admin Bar: from n/a through 2.0.
Title WordPress WP Hide Admin Bar plugin <= 2.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:50.250Z

Reserved: 2025-03-11T08:09:27.024Z

Link: CVE-2025-28910

cve-icon Vulnrichment

Updated: 2025-03-12T17:19:17.016Z

cve-icon NVD

Status : Deferred

Published: 2025-03-11T21:15:48.650

Modified: 2026-06-17T09:04:51.870

Link: CVE-2025-28910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:45:33Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)