Impact
The WP Hide Admin Bar plugin does not validate anti‑CSRF tokens for certain administrative requests. This flaw permits an attacker to construct a link or form that, when visited or submitted by an authenticated WordPress user, sends a request to the plugin’s endpoints without a valid token, potentially changing plugin settings or triggering plugin‑controlled actions.
Affected Systems
Any WordPress site that has installed the WP Hide Admin Bar plugin version 2.0 or earlier, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Typical exploitation would rely on social engineering or a compromised site to host a crafted link or form that the victim visits, resulting in an unauthorized request being processed by the plugin.
OpenCVE Enrichment
EUVD