Junglewise Threat Intelligence

CVE-2025-62087: Web Builder Sticky Notes for WP Dashboard broken access control

CVE-2025-62087 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

Sticky Notes for WP Dashboard is a WordPress plugin that provides dashboard note-taking functionality for site administrators. A broken access control vulnerability allows users with subscriber-level permissions to access or modify notes and data they shouldn't be able to view, potentially exposing sensitive information stored within the plugin.

Technical details

A broken access control vulnerability in the Sticky Notes for WP Dashboard WordPress plugin (versions <= 1.2.4) fails to properly validate user permissions before allowing access to certain plugin features and data. The vulnerability requires an attacker to be authenticated as a subscriber or higher privilege level on the WordPress site. By exploiting the missing authorization checks, an attacker can bypass intended access controls and view or perform actions restricted to higher-privilege users. The vulnerability has been patched in version 1.2.5 and later.

Affected products

  • Web Builder Sticky Notes for WP Dashboard through 1.2.4

Timeline

  • 2025-10-15: disclosed: Reported to Patchstack
  • 2025-12-31: advisory: Published by Patchstack
  • 2025-12-31: patched: Version 1.2.5 released

References