Home

Description

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

PUBLISHED Reserved 2024-01-22 | Published 2025-05-15 | Updated 2025-05-16 | Assigner WPScan

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 1.0.11
affected

Credits

Pedro Cuco (Illex) finder

WPScan coordinator

References

wpscan.com/...rability/6e6afe50-27f9-41fa-a94b-f44df0850e2c/ exploit vdb-entry technical-description

cve.org (CVE-2023-7239)

nvd.nist.gov (CVE-2023-7239)

Download JSON