
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62087 is a Missing Authorization (Broken Access Control) vulnerability in the "Sticky Notes for WP Dashboard" WordPress plugin developed by Web Builder 143. It allows authenticated low-privileged users (Subscriber-level) to exploit incorrectly configured access control security levels to access restricted data. All versions through 1.2.4 are affected; version 1.2.5 contains the fix. The vulnerability was published on December 31, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing certain privileged actions or exposing data. Specifically, the plugin does not enforce adequate authorization checks on one or more WordPress dashboard functions, allowing a Subscriber-level user to access sticky notes or related data that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, and no user interaction, making it straightforward to exploit for any authenticated WordPress user (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker to read sensitive information stored in the WordPress dashboard's sticky notes, which may include internal communications, credentials, or other confidential data left by administrators. The impact is limited to confidentiality (low), with no direct integrity or availability consequences. While the scope is contained to the affected WordPress instance, exposed notes could facilitate further attacks such as privilege escalation or targeted social engineering (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability was discovered by researcher "Legion Hunter" and reported to Patchstack on October 15, 2025, with no CISA KEV catalog listing. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).
https://target.com/wp-content/plugins/wb-sticky-notes/readme.txt./wp-admin/admin-ajax.php) associated with the wb-sticky-notes plugin outside of normal dashboard usage patterns.wb-sticky-notes.The vendor has released version 1.2.5 of the Sticky Notes for WP Dashboard plugin, which resolves this vulnerability. Site administrators should update the plugin to version 1.2.5 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. If an immediate update is not possible, consider deactivating the plugin until the patch can be applied, or use Patchstack's virtual patching feature to block exploitation without requiring a code update (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."