Back

HIGH

wp-dashboard-notes < 1.0.11 - Contributor+ Arbitrary Private Notes Update via IDOR

Published May 15, 2025

Description

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published May 15, 2025
Updated May 16, 2025
Reserved Jan 22, 2024
CISA Vulnrichment
Updated May 16, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a