Impact
The Page & Post Notes plugin contains a missing capability check on the 'yydev_notes_save_dashboard_data' function in all releases up to 1.3.4. Authenticated users with Subscriber-level access or higher can exploit this flaw to modify or delete notes stored by the plugin. The change of note content can alter information presented to site visitors, compromising content integrity.
Affected Systems
The affected system is the Page & Post Notes WordPress plugin developed by yydevelopment. All releases up to and including version 1.3.4 are vulnerable; site administrators should verify the installed plugin version.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated, with at least Subscriber privileges, to exploit the flaw by invoking the backend endpoint that processes note updates or deletions.
OpenCVE Enrichment