Description
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 01 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeroensormani
Jeroensormani wp Dashboard Notes |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Jeroensormani
Jeroensormani wp Dashboard Notes |
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wp-dashboard-notes
Wp-dashboard-notes wp Dashboard Notes |
|
| CPEs | cpe:2.3:a:wp-dashboard-notes:wp_dashboard_notes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wp-dashboard-notes
Wp-dashboard-notes wp Dashboard Notes |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-24T20:02:50.419Z
Reserved: 2024-01-02T11:10:43.400Z
Link: CVE-2023-7198
Updated: 2024-08-02T08:57:35.513Z
Status : Analyzed
Published: 2024-02-27T09:15:37.350
Modified: 2025-05-01T14:38:28.360
Link: CVE-2023-7198
No data.
OpenCVE Enrichment
No data.
Weaknesses