Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page

Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jan w Oleju. Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3

Hide Admin Bar Based On User Roles < 3.1.0 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page banner
Latestv7.2.5

Hide Admin Bar Based on User Roles – Disable the WordPress Toolbar by Role, Device or Page

Ankit Panchal

Author

Ankit Panchal

3.9(20)
78/100
Last Updated
2026-08-23 (20d ago)
Active Installs
20,000+
Downloads
844,447
Requires WP
5.5+
Requires PHP
5.6+
Tested up to
WP 7.1
Created
2018-07-16 (8y ago)

The complete WordPress admin bar control plugin Hide Admin Bar Based On User Roles gives you complete control over who sees the WordPress admin bar (toolbar) on the frontend of your site. Remove the admin bar for subscribers, hide the toolbar for WooCommerce customers, disable it for all users, or build precise visibility rules by role, capability, device, page, or time — all without writing a single line of code. The plugin is lightweight, developer-friendly, and works immediately upon activation — no configuration required to get started. Trusted on 20,000+ active WordPress sites. Simple but great plugin. 🙂 – wptoolsdev Works flawlessly! 🙂 – thebrazeneye Why hide the WordPress admin bar? The black toolbar at the top of your site is useful for admins — but for everyone else it exposes backend links, breaks your design, and confuses non-technical users. Hiding it is essential for: Membership sites – give members a clean, frontend-only experience with no WordPress branding WooCommerce stores – stop showing the toolbar to customers after they log in LMS & course platforms – keep students focused on your content, not the WordPress UI Client websites – hand over polished sites where editors see only what they need Communities & directories – hide backend access hints from registered users Anyone who wants a cleaner frontend – remove the admin bar without touching functions.php 🚀 Key Features (Free) Hide for All Users: Completely remove the admin bar from the frontend for everyone. Hide for Guests: Ensure non-logged-in visitors never see the toolbar. Role-Based Hiding: Select specific roles (e.g., Subscriber, Customer, Editor) to hide the bar for. Capability-Based Hiding: Hide the bar based on WordPress capabilities (e.g., hide for anyone who cannot manage_options). Lightweight & Fast: Zero bloat — no external requests, no database overhead on the frontend. 🏆 Premium Features (Pro) Unlock advanced visibility logic with the Pro version: Page-Based Targeting: Show or hide the admin bar only on specific URLs, post types, or page templates. Device Detection: Hide the toolbar on Mobile or Tablet to save screen space, while keeping it on Desktop. Per-User Overrides: Manually force the admin bar to show or hide for individual user accounts. Time-Based Visibility: Automatically hide the bar during specific hours of the day. Smart Redirects: Redirect users to the homepage or a custom URL when they try to access the backend. Inactivity Auto-Hide: Automatically slide the toolbar away after a configurable period of inactivity. Import / Export Settings: Back up and migrate your configuration across sites in one click. Works with your setup Hide Admin Bar Based on User Roles works with any theme and any plugin that registers user roles — including WooCommerce (Customer role), membership plugins, LMS plugins, and custom roles. Fully compatible with Elementor, Divi, Beaver Builder, Bricks, and WordPress Multisite. You can check our other plugins: All-in-One WordPress Toolkit for SEO, Security, Customization, and Performance Like Dislike For WP Disable Block Editor FullScreen mode NoteFlow – Smart Notes Manager for WordPress Admin Page Visit Counter Analytics – Google Analytics Alternative

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C