CVE-2023-7239

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:*

History

09 Jun 2025, 18:31

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/6e6afe50-27f9-41fa-a94b-f44df0850e2c/ - () https://wpscan.com/vulnerability/6e6afe50-27f9-41fa-a94b-f44df0850e2c/ - Exploit, Third Party Advisory
First Time Jeroensormani wp Dashboard Notes
Jeroensormani
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:*

16 May 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento WP Dashboard Notes para WordPress, anterior a la versión 1.0.11, no valida que el usuario tenga acceso al parámetro post_id en su acción AJAX wpdn_update_note. Esto permite a los usuarios con rol de colaborador o superior actualizar notas creadas por otros usuarios.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-09 18:31


NVD link : CVE-2023-7239

Mitre link : CVE-2023-7239

CVE.ORG link : CVE-2023-7239


JSON object : View

Products Affected

jeroensormani

  • wp_dashboard_notes