Cross-Site Request Forgery Vulnerability in TopBar Plugin for WordPress
CVE-2025-10300
4.3MEDIUM
What is CVE-2025-10300?
The TopBar plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation within the fme_nb_topbar_save_settings() function. This flaw allows attackers to send forged requests that could alter the plugin's settings. If an administrator is deceived into clicking a malicious link, their actions could inadvertently grant unauthorized access, leading to potential misconfigurations within the WordPress installation.
Affected Version(s)
TopBar * <= 1.0.0