{"id":18551956,"date":"2025-07-12T04:49:31","date_gmt":"2025-07-12T04:49:31","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/cross-site-request-forgery-13\/"},"modified":"2025-07-12T04:49:31","modified_gmt":"2025-07-12T04:49:31","slug":"cross-site-request-forgery-13","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/cross-site-request-forgery-13\/","title":{"rendered":"Cross-Site Request Forgery"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Is there going to be a fix for the security risk? &#8220;The Disable Admin Notices individually plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.&#8221;<\/p>\n","protected":false},"template":"","class_list":["post-18551956","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18551956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18551956\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18551956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}