CVE-2023-7239

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:*

History

09 Jun 2025, 18:31

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-09 18:31


NVD link : CVE-2023-7239

Mitre link : CVE-2023-7239

CVE.ORG link : CVE-2023-7239


JSON object : View

Products Affected

jeroensormani

  • wp_dashboard_notes