WordPress Show Notice or Message on Admin Area Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Show Notice or Message on Admin Area plugin, affecting versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to, potentially leading to Stored Cross-Site Scripting (XSS) issues.

Impact

Exploitation of this vulnerability could enable Stored Cross-Site Scripting, where injected scripts are executed in the context of the user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.