« Volver al listado

CVE-2023-7198

Estado: AnalizadaMedia (4.3)—

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-7198",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-7198",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-27T15:32:50.184805Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "WP Dashboard Notes",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.11",
              "versionType": "semver"
            }
          ],
          "collectionURL": "https://wordpress.org/plugins",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:wp-dashboard-notes:wp_dashboard_notes:*:*:*:*:*:*:*:*"
          ],
          "vendor": "wp-dashboard-notes",
          "product": "wp_dashboard_notes",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-27T09:15:37.350",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/75fbee63-d622-441f-8675-082907b0b1e6/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/75fbee63-d622-441f-8675-082907b0b1e6/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data."
    },
    {
      "lang": "es",
      "value": "El complemento WP Dashboard Notes de WordPress anterior a 1.0.11 es vulnerable a referencias de objetos directos inseguros (IDOR) en el parámetro post_id=. Los usuarios autenticados pueden eliminar notas privadas asociadas con diferentes cuentas de usuario. Esto plantea un riesgo de seguridad importante, ya que viola el principio de privilegio mínimo y compromete la integridad y privacidad de los datos del usuario."
    }
  ],
  "lastModified": "2026-06-17T06:52:17.757",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jeroensormani:wp_dashboard_notes:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4503DC31-C24B-4A80-A58A-4F6E28CF5FEB",
              "versionEndExcluding": "1.0.11"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}