Executive brief
The User Admin Simplifier plugin for WordPress, which allows administrators to customize the dashboard interface for users, contains a security flaw that could allow an attacker to reset user interface settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely delete or overwrite stored menu and admin-bar configurations. While this does not directly expose sensitive data, it can disrupt administrative workflows and damage the customized user experience of the site.
Technical details
The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'useradminsimplifier_options_page' function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers the 'uas_save_admin_options()' function. This results in the 'useradminsimplifier_options' database entry being overwritten, effectively resetting or permanently deleting any user's stored menu and admin-bar configurations. The vulnerability affects all versions up to and including 3.0.0.
Affected products
- adamsilverstein User Admin Simplifier up to, and including, 3.0.0
Timeline
- 2026-06-19: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/user-admin-simplifier/tags/1.0.0/useradminsimplifier.php
- https://plugins.trac.wordpress.org/browser/user-admin-simplifier/tags/1.0.0/useradminsimplifier.php
- https://plugins.trac.wordpress.org/browser/user-admin-simplifier/tags/1.0.0/useradminsimplifier.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3566637%40user-admin-simplifier&new=3566637%40user-admin-simplifier&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0920fc70-1c4b-45ff-86f6-14640286b5e6?source=cve