PT-2025-21387 · WordPress · Wp Dashboard Notes
Pedro Cuco
·
Published
2025-05-15
·
Updated
2025-06-09
·
CVE-2023-7239
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
WP Dashboard Notes versions prior to 1.0.11
Description:
The issue concerns the WP Dashboard Notes WordPress plugin, where it fails to validate user access to the
post id parameter in its wpdn update note AJAX action. This allows users with a role of contributor and above to update notes created by other users.Recommendations:
For versions prior to 1.0.11, update to version 1.0.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the
wpdn update note AJAX action to prevent unauthorized note updates.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Dashboard Notes