Cross-Site Request Forgery in Top Bar Notification Plugin for WordPress
CVE-2025-12412
What is CVE-2025-12412?
The Top Bar Notification plugin for WordPress has a vulnerability that exposes it to Cross-Site Request Forgery (CSRF) attacks. This vulnerability originates from missing or improperly implemented nonce validation in the tbn_ajax_add() function. As a result, unauthenticated attackers can potentially alter the plugin's settings and inject harmful scripts through forged requests. The attack requires that a site administrator is deceived into executing a specific action, such as clicking a link, thus making it crucial for users to be aware of this exploit to safeguard their sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Top Bar Notification * <= 1.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved