What the vulnerability does
01Description
Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
Sticky Notes for WP Dashboard versions 1.2.4 and earlier lack proper authorization checks, allowing authenticated users to read sensitive note data they should not access. An attacker with a low-privilege WordPress account can view other users' sticky notes without additional interaction. Update to a version newer than 1.2.4 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read other users' sticky notes and any sensitive information stored in them.
Potential impact on your site
04Site Impact
Private notes and sensitive information stored by site admins or editors may be exposed to lower-privilege users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
December 31, 2025
CVE published
May 12, 2026
Record updated