Description
The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-02-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Configuration Modification via CSRF
Action: Update Plugin
AI Analysis

Impact

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress contains a cross‑site request forgery flaw caused by missing nonce validation in the showPageContent() function. The flaw enables an unauthenticated attacker who can trick a site administrator into clicking a link to add arbitrary URLs to the blocked redirects list. The primary impact is unauthorized modification of the plugin’s configuration, which can redirect visitors or alter site behavior. Although the vulnerability does not provide remote code execution, the capability to change redirect rules can facilitate phishing or other indirect attacks. The vulnerability is rated with a CVSS score of 4.3, indicating moderate severity.

Affected Systems

The affected product is the themeisle Disable Admin Notices – Hide Dashboard Notifications WordPress plugin, all releases up to and including version 1.4.2. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 4.3 and an EPSS of less than one percent suggest a moderate but not high likelihood of exploitation. The flaw requires a social‑engineering component: an attacker must persuade a site administrator to trigger a forged request. The absence of the vulnerability from CISA’s KEV catalog further indicates that known exploits are not publicized. A compromise would allow an attacker to inject malicious redirect URLs, potentially redirecting visitors to malicious sites or intercepting traffic. The vulnerability is identified as CWE‑352, a cross‑site request forgery weakness.

Generated by OpenCVE AI on April 15, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin update that addresses the CSRF issue.
  • If an update is unavailable, restrict administrator accounts to trusted users and monitor for forged requests using a security plugin.
  • Manually review the blocked redirects list and remove any unknown or suspicious entries.

Generated by OpenCVE AI on April 15, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Themeisle
Themeisle disable Admin Notices – Hide Dashboard Notifications
Wordpress
Wordpress wordpress
Vendors & Products Themeisle
Themeisle disable Admin Notices – Hide Dashboard Notifications
Wordpress
Wordpress wordpress

Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Themeisle Disable Admin Notices – Hide Dashboard Notifications
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:16:33.594Z

Reserved: 2026-02-12T15:19:11.579Z

Link: CVE-2026-2410

cve-icon Vulnrichment

Updated: 2026-02-25T21:11:33.380Z

cve-icon NVD

Status : Deferred

Published: 2026-02-25T10:16:18.697

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-2410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:00:07Z

Weaknesses