The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 01 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Jeroensormani Jeroensormani wp Dashboard Notes | |
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Jeroensormani Jeroensormani wp Dashboard Notes | 
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Wp-dashboard-notes Wp-dashboard-notes wp Dashboard Notes | |
| CPEs | cpe:2.3:a:wp-dashboard-notes:wp_dashboard_notes:*:*:*:*:*:*:*:* | |
| Vendors & Products | Wp-dashboard-notes Wp-dashboard-notes wp Dashboard Notes | |
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: WPScan
Published: 2024-02-27T08:30:27.438Z
Updated: 2025-03-24T20:02:50.419Z
Reserved: 2024-01-02T11:10:43.400Z
Link: CVE-2023-7198
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T08:57:35.513Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-02-27T09:15:37.350
Modified: 2025-05-01T14:38:28.360
Link: CVE-2023-7198
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow