Impact
The Remove meta boxes per user role plugin for WordPress contains a Cross‑Site Request Forgery flaw caused by missing or incorrect nonce validation on the "remove-meta-boxes-per-user-role" settings page. An unauthenticated attacker can craft a forged request and cause an administrator, if tricked into clicking a link or visiting a malicious URL, to unintentionally submit the request and modify or reset the plugin’s per‑role meta box visibility settings.
Affected Systems
WordPress sites that have the Remove meta boxes per user role plugin installed with version 1.01 or earlier are affected. The vulnerability is associated with the mr_mat vendor and applies to all releases up to and including 1.01.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the moderate range. No EPSS score is available, and it is not listed in the CISA KEV catalog. Exploitation requires only that an attacker persuade a site administrator to submit a forged request; no additional credentials or system access is necessary. Successful exploitation results in unauthorized changes to the plugin’s configuration, affecting how meta boxes appear in the WordPress admin interface.
OpenCVE Enrichment