Description
Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top Bar: from n/a through <= 3.3.
Published: 2025-03-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PluginOps Top Bar plugin contains a missing authorization flaw that allows an attacker to bypass the plugin’s configured security settings. The vulnerability is classified as CWE-862, indicating that access control checks are improperly enforced. As a result, an attacker who can reach the plugin’s administrative interfaces may gain unauthorized abilities that are typically reserved for privileged users, such as modifying site settings or accessing sensitive content. The official description lists the flaw as an "Incorrectly Configured Access Control Security Levels" issue. No evidence of more severe impacts, such as remote code execution, is provided in the data.

Affected Systems

WordPress sites that have the PluginOps Top Bar (ultimate-bar) plugin installed at version 3.3 or earlier are vulnerable. The affected versions are indicated as "n/a through <= 3.3", meaning any installation that has not been upgraded beyond the 3.3 release may be impacted.

Risk and Exploitability

The plugin’s vulnerability has a CVSS score of 5.3, indicating a moderate risk level. The EPSS score is listed as < 1%, suggesting that exploitation is unlikely but not impossible. The flaw is not currently included in the CISA KEV catalog. The likely attack vector is a web-based request to the plugin’s administrative endpoints that rely on the plugin’s own access control logic. If an attacker can create or send a crafted request to those paths, they may circumvent the plugin’s intended restrictions. Given the lack of a publicly documented exploit and the low EPSS, the risk is moderate; however, the potential for unauthorized changes to the site still justifies remediation.

Generated by OpenCVE AI on May 1, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PluginOps Top Bar plugin to the latest available version (greater than 3.3)
  • If an upgrade is not immediately possible, disable or restrict access to the plugin’s administrative endpoints using a web application firewall or host‑based access controls
  • Review and enforce the default access control settings for the plugin, ensuring that only privileged WordPress users can reach its management functions

Generated by OpenCVE AI on May 1, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7937 Missing Authorization vulnerability in PluginOps Top Bar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Top Bar: from n/a through 3.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PluginOps Top Bar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Top Bar: from n/a through 3.3. Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top Bar: from n/a through <= 3.3.
Title WordPress Top Bar - <= <=3.3 Broken Access Control Vulnerability WordPress Top Bar plugin <= 3.3 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 24 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PluginOps Top Bar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Top Bar: from n/a through 3.3.
Title WordPress Top Bar - <= <=3.3 Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:54.656Z

Reserved: 2025-03-24T13:00:24.105Z

Link: CVE-2025-30581

cve-icon Vulnrichment

Updated: 2025-03-24T14:20:04.704Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:30.217

Modified: 2026-06-17T09:08:57.600

Link: CVE-2025-30581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:30:08Z

Weaknesses