Unauthorized Modification Vulnerability in Page & Post Notes Plugin by WordPress
CVE-2025-12527
4.3MEDIUM
What is CVE-2025-12527?
The Page & Post Notes plugin for WordPress is susceptible to an unauthorized modification vulnerability. This issue arises from a missing capability check in the 'yydev_notes_save_dashboard_data' function, affecting all versions up to and including 1.3.4. Authenticated users with Subscriber-level access and higher can exploit this flaw to modify notes, potentially leading to information tampering and data integrity issues within the WordPress environment.
Affected Version(s)
Page & Post Notes * <= 1.3.4