WORDFENCE-6aab08c1-20db-46a2-b93a-d864bb57bf4d
medium
📛 Threat Title
WP-TopBar <= 4.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Description
The WP-TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.02. This is due to missing or incorrect nonce validation in the admin pages. This makes it possible for unauthenticated attackers to gain otherwise restricted access and perform subsequent Stored Cross-Site Scripting attacks via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Affected software — plugin: WP-TopBar (affected: *-4.02). CVSS 6.1 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: WP-TopBarWordfence
Update to version 4.03, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.