Cross-Site Request Forgery in Frontend User Notes Plugin for WordPress
CVE-2026-7047

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 June 2026

What is CVE-2026-7047?

The Frontend User Notes plugin for WordPress is affected by a Cross-Site Request Forgery vulnerability due to improper nonce validation in the funp_ajax_modify_notes function. This flaw allows unauthenticated attackers to potentially trick logged-in users into performing unintended actions, such as overwriting their own notes. This occurs when the attacker convinces an authorized user to visit a malicious site that triggers a forged request to wp_update_post(), leading to unauthorized changes to notes linked to the targeted user. Importantly, this attack is restricted to the notes belonging to the victim, preventing access to notes owned by other users.

Affected Version(s)

Frontend User Notes 0 <= 2.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohamed Wajih Hichri
.