Description
Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4.
Published: 2025-12-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw identified as CWE-862 that allows users to access or modify the Sticky Notes for WP Dashboard plugin beyond their intended permissions. Without proper access controls, an attacker could view or change note content, potentially exposing sensitive information or disrupting the user interface. The impact is confined to the data handled by the plugin and does not immediately provide remote code execution or cross‑site scripting capabilities. Based on the description, it is inferred that the flaw exists in the plugin's handling of security levels and is exploitable via the web interface that authenticates WordPress users.

Affected Systems

WordPress installations running the Sticky Notes for WP Dashboard plugin version 1.2.4 or earlier. The vendor is Web Builder 143 and the affected product is Sticky Notes for WP Dashboard. All users of these installations are subject to the flaw, regardless of WordPress user role.

Risk and Exploitability

The CVSS score of 4.3 classifies the bug as moderate. The EPSS score of less than 1% indicates a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw enables privilege escalation for authenticated users in WordPress, an attacker could gain unauthorized access to note data or alter content if they can log in or impersonate a user. The most likely attack vector is the plugin’s administrative interface, requiring access to a WordPress account with any level of privileges but no additional system privileges.

Generated by OpenCVE AI on April 29, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sticky Notes for WP Dashboard to a version newer than 1.2.4, ensuring the fix for the authorization flaw is applied.
  • If an upgrade is not possible, continue using the plugin in a read‑only or disabled state until a patch is available.
  • Apply the principle of least privilege to all WordPress user accounts and audit plugin permissions to confirm that only trusted administrators can access or modify sticky notes.

Generated by OpenCVE AI on April 29, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through 1.2.4. Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Web Builder 143
Web Builder 143 sticky Notes For Wp Dashboard
Wordpress
Wordpress wordpress
Vendors & Products Web Builder 143
Web Builder 143 sticky Notes For Wp Dashboard
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through 1.2.4.
Title WordPress Sticky Notes for WP Dashboard plugin <= 1.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Web Builder 143 Sticky Notes For Wp Dashboard
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T01:06:52.676Z

Reserved: 2025-10-07T15:34:56.057Z

Link: CVE-2025-62087

cve-icon Vulnrichment

Updated: 2025-12-31T16:31:16.785Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T16:15:44.280

Modified: 2026-04-23T15:34:30.927

Link: CVE-2025-62087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:00:07Z

Weaknesses