PT-2025-21387 · WordPress · Wp Dashboard Notes

Pedro Cuco

·

Published

2025-05-15

·

Updated

2025-06-09

·

CVE-2023-7239

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: WP Dashboard Notes versions prior to 1.0.11
Description: The issue concerns the WP Dashboard Notes WordPress plugin, where it fails to validate user access to the post id parameter in its wpdn update note AJAX action. This allows users with a role of contributor and above to update notes created by other users.
Recommendations: For versions prior to 1.0.11, update to version 1.0.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the wpdn update note AJAX action to prevent unauthorized note updates.

Exploit

Fix

Related Identifiers

CVE-2023-7239

Affected Products

Wp Dashboard Notes