Executive brief
Sticky Notes for WP Dashboard is a WordPress plugin that provides dashboard note-taking functionality for site administrators. A broken access control vulnerability allows users with subscriber-level permissions to access or modify notes and data they shouldn't be able to view, potentially exposing sensitive information stored within the plugin.
Technical details
A broken access control vulnerability in the Sticky Notes for WP Dashboard WordPress plugin (versions <= 1.2.4) fails to properly validate user permissions before allowing access to certain plugin features and data. The vulnerability requires an attacker to be authenticated as a subscriber or higher privilege level on the WordPress site. By exploiting the missing authorization checks, an attacker can bypass intended access controls and view or perform actions restricted to higher-privilege users. The vulnerability has been patched in version 1.2.5 and later.
Affected products
- Web Builder Sticky Notes for WP Dashboard through 1.2.4
Timeline
- 2025-10-15: disclosed: Reported to Patchstack
- 2025-12-31: advisory: Published by Patchstack
- 2025-12-31: patched: Version 1.2.5 released