Cross-Site Request Forgery in Top Bar Notification Plugin for WordPress
CVE-2025-12412 
6.1MEDIUM
What is CVE-2025-12412?
The Top Bar Notification plugin for WordPress has a vulnerability that exposes it to Cross-Site Request Forgery (CSRF) attacks. This vulnerability originates from missing or improperly implemented nonce validation in the tbn_ajax_add() function. As a result, unauthenticated attackers can potentially alter the plugin's settings and inject harmful scripts through forged requests. The attack requires that a site administrator is deceived into executing a specific action, such as clicking a link, thus making it crucial for users to be aware of this exploit to safeguard their sites.
Affected Version(s)
Top Bar Notification * <= 1.12