Description
Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.This issue affects Admin Notes: from n/a through <= 1.1.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‐site request forgery (CSRF) weakness in the minhlaobao Admin Notes plugin version 1.1 and earlier allows an attacker to force an authenticated user to perform actions through the plugin. The CVE notes that the vulnerability permits forged HTTP requests, but does not specify which plugin operations can be invoked. Based on the plugin’s typical functionality, an attacker could likely create, edit, or delete notes, thereby altering content that is normally restricted to administrators. This weakness is identified as CWE‑352, which underlines the absence of a CSRF token or sufficient user‑consent verification.

Affected Systems

The issue affects the Admin Notes plugin by minhlaobao, any WordPress installation running version 1.1 or older. No other plugins or vendor products are listed as affected. Administrators who use the plugin to manage notes on a site that has not been patched or updated are exposed.

Risk and Exploitability

The CVSS base score is 4.3, indicating a moderate risk level for confidentiality, integrity, and availability. The EPSS score of less than 1 % signals that the compromise of this weakness by a public exploit is considered unlikely, and the vulnerability is not present in the CISA KEV catalog. Typical CSRF exploitation would require that an administrator is authenticated in the victim’s browser and is tricked into visiting a specially crafted URL or loading a malicious form. Though no public exploit is documented in the references, the inference is that the attack vector would be via a GET or POST request that triggers the plugin’s note‑management endpoints.

Generated by OpenCVE AI on May 1, 2026 at 07:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Admin Notes plugin to the latest release (1.2 or newer) if a patch that removes the CSRF flaw is available.
  • If an update is not available or imminent, disable or delete the plugin so that the vulnerable code is no longer executed.
  • While the plugin remains active, limit access to the administration area to a minimal set of trusted users and enforce WordPress CSRF protections – for example, ensure all form submissions use the same‑site cookie attribute and the built‑in nonce mechanism so that forged requests are rejected.

Generated by OpenCVE AI on May 1, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17150 Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1. Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.This issue affects Admin Notes: from n/a through <= 1.1.
Title WordPress Admin Notes <=1.1 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Admin Notes plugin <=1.1 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.
Title WordPress Admin Notes <=1.1 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:04.878Z

Reserved: 2025-06-04T15:44:57.576Z

Link: CVE-2025-49446

cve-icon Vulnrichment

Updated: 2025-06-06T15:20:23.045Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:58.330

Modified: 2026-04-23T15:31:41.913

Link: CVE-2025-49446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:45:06Z

Weaknesses