First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved allows Stored XSS. This issue affects WordPress Admin Bar Improved: from n/a through 3.3.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=3.3.5 | ||
<=3.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2025-30552 vulnerability has a high severity rating due to its potential for Cross-Site Request Forgery (CSRF) and Stored XSS exploits.
To fix CVE-2025-30552, upgrade the Donald Gilbert WordPress Admin Bar Improved plugin to version 3.3.6 or later.
CVE-2025-30552 affects all versions of the Donald Gilbert WordPress Admin Bar Improved plugin from n/a through 3.3.5.
CVE-2025-30552 enables Cross-Site Request Forgery (CSRF) attacks that can lead to Stored XSS vulnerabilities.
The vendor of the vulnerable product related to CVE-2025-30552 is Donald Gilbert.