WPIntell

Source evidence

Security Issue

Disable Admin Notices – Hide Dashboard Notifications · support · 2025-09-28T13:26:00+00:00

mixedsentiment
highseverity
0.95relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

2 / 28 rows with source links

7.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Kevin Forster resolved
Hi, Installed your plug-in yesterday and all is working as it should BUT Jetpack is advising me: The installed version of Disable Admin Notices Individually (1.3.6) has a known security vulnerability. Do you have a fix planned? Seems a shame to disable the plugin that works….. Thanks This topic was modified 8 months ago by Kevin Forster . The page I need help with: [ log in to see the link] Wordfence is also warning about a critical security failure with Disable 🙁 Hi @vegancake , @macwillard , Thank you for taking the time to report this issue and helping us keep the plugin secure. Our development team is working on a fix and will include it in the next release. Best regards, I would like to inform you about a security issue reported by my website’s security plugin regarding “Disable Admin Notices individually”. The vulnerability affects all versions up to 1.3.6 and has been publicly disclosed as a Cross Site Request Forgery (CSRF) (CVE-2024-52420). Currently, there is no fix available for this vulnerability, and the only recommended mitigation is to deactivate the plugin. This situation is concerning for users who rely on your plugin for WordPress administration. Could you please provide an update on when a security patch will be released, or if there are any temporary mitigation steps we could apply to maintain security while using your plugin? Best regards, Antonio Hi, it’s been over a month now since the vulnerability has been reported. I see a fix has still not been released. Can you please clarify your fixed status urgently. Hi @vegancake @darrenmcentee @iconet @macwillard , The vulnerability was already patched with the latest release, we also informed the security channels to verify it so should soon disappear from warnings like those you see from Wordfence. Thank you for your patience.

Comments

5 shown
KittyFlynn 2025-10-19T15:04:00+00:00

Wordfence is also warning about a critical security failure with Disable 🙁

Stefan Cotitosu 2025-10-20T07:33:00+00:00

Hi @vegancake , @macwillard , Thank you for taking the time to report this issue and helping us keep the plugin secure. Our development team is working on a fix and will include it in the next release. Best regards,

iconet 2025-10-23T13:21:00+00:00

I would like to inform you about a security issue reported by my website’s security plugin regarding “Disable Admin Notices individually”. The vulnerability affects all versions up to 1.3.6 and has been publicly disclosed as a Cross Site Request Forgery (CSRF) (CVE-2024-52420). Currently, there is no fix available for this vulnerability, and the only recommended mitigation is to deactivate the plugin. This situation is concerning for users who rely on your plugin for WordPress administration. Could you please provide an update on when a security patch will be released, or if there are any temporary mitigation steps we could apply to maintain security while using your plugin? Best regards, Antonio

dmac 2025-11-05T19:03:00+00:00

Hi, it’s been over a month now since the vulnerability has been reported. I see a fix has still not been released. Can you please clarify your fixed status urgently.

Vytis 2025-11-07T18:29:00+00:00

Hi @vegancake @darrenmcentee @iconet @macwillard , The vulnerability was already patched with the latest release, we also informed the security channels to verify it so should soon disappear from warnings like those you see from Wordfence. Thank you for your patience.