CVE-2023-7198
WPDashboardNotes < 1.0.11 - Unauthorised Deletion of Private Notes
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.
El complemento WP Dashboard Notes de WordPress anterior a 1.0.11 es vulnerable a referencias de objetos directos inseguros (IDOR) en el parámetro post_id=. Los usuarios autenticados pueden eliminar notas privadas asociadas con diferentes cuentas de usuario. Esto plantea un riesgo de seguridad importante, ya que viola el principio de privilegio mínimo y compromete la integridad y privacidad de los datos del usuario.
The WP Dashboard Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.10 via the 'post_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers to delete private notes associated with other user accounts.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-12-19 CVE Published
- 2024-01-02 CVE Reserved
- 2024-02-28 EPSS Updated
- 2024-08-08 CVE Updated
- 2024-08-08 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/75fbee63-d622-441f-8675-082907b0b1e6 | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | WP Dashboard Notes Search vendor "Unknown" for product "WP Dashboard Notes" | < 1.0.11 Search vendor "Unknown" for product "WP Dashboard Notes" and version " < 1.0.11" | en |
Affected
|