What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area show-notice-or-message-on-admin-area allows Stored XSS.This issue affects Show notice or message on admin area: from n/a through <= 2.0.
Explanation of Vulnerability in Simple Terms
02Summary
A cross-site request forgery (CSRF) vulnerability in Show notice or message on admin area versions 2.0 and earlier allows an attacker to perform unauthorized actions in the WordPress admin area on behalf of an authenticated user. The attacker must trick a logged-in site administrator into visiting a malicious webpage. The vulnerability can lead to unauthorized changes to site settings or content.
What an attacker can do
03Attacker Capabilities
Perform unauthorized admin actions on behalf of a logged-in administrator without their knowledge.
Potential impact on your site
04Site Impact
An attacker could modify site settings, content, or user accounts if they trick an admin into visiting a malicious link.
Conditions required to exploit
05Prerequisites
Administrator must be logged in and visit an attacker-controlled webpage while authenticated.
Key dates
06Disclosure timeline
February 7, 2025
CVE published
April 28, 2026
Record updated