Cross-Site Request Forgery in Frontend User Notes Plugin for WordPress
CVE-2026-7047
4.3MEDIUM
What is CVE-2026-7047?
The Frontend User Notes plugin for WordPress is affected by a Cross-Site Request Forgery vulnerability due to improper nonce validation in the funp_ajax_modify_notes function. This flaw allows unauthenticated attackers to potentially trick logged-in users into performing unintended actions, such as overwriting their own notes. This occurs when the attacker convinces an authorized user to visit a malicious site that triggers a forged request to wp_update_post(), leading to unauthorized changes to notes linked to the targeted user. Importantly, this attack is restricted to the notes belonging to the victim, preventing access to notes owned by other users.
Affected Version(s)
Frontend User Notes 0 <= 2.1.1