CVE-2025-62087
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62087 is a Missing Authorization (Broken Access Control) vulnerability in the "Sticky Notes for WP Dashboard" WordPress plugin developed by Web Builder 143. It allows authenticated low-privileged users (Subscriber-level) to exploit incorrectly configured access control security levels to access restricted data. All versions through 1.2.4 are affected; version 1.2.5 contains the fix. The vulnerability was published on December 31, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing certain privileged actions or exposing data. Specifically, the plugin does not enforce adequate authorization checks on one or more WordPress dashboard functions, allowing a Subscriber-level user to access sticky notes or related data that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, and no user interaction, making it straightforward to exploit for any authenticated WordPress user (Patchstack).

Impact

Successful exploitation allows a low-privileged authenticated attacker to read sensitive information stored in the WordPress dashboard's sticky notes, which may include internal communications, credentials, or other confidential data left by administrators. The impact is limited to confidentiality (low), with no direct integrity or availability consequences. While the scope is contained to the affected WordPress instance, exposed notes could facilitate further attacks such as privilege escalation or targeted social engineering (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability was discovered by researcher "Legion Hunter" and reported to Patchstack on October 15, 2025, with no CISA KEV catalog listing. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Sticky Notes for WP Dashboard" plugin (wb-sticky-notes) version 1.2.4 or earlier, using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/wb-sticky-notes/readme.txt.
  2. Obtain low-privileged access: Register or log in as a Subscriber-level user on the target WordPress site (many sites allow open registration).
  3. Identify vulnerable endpoint: Locate the plugin's AJAX action or REST API endpoint that handles sticky note retrieval without proper capability checks — typically discoverable by reviewing the plugin's source code or intercepting dashboard requests.
  4. Send unauthorized request: Issue an authenticated HTTP request (with a valid nonce or session cookie) to the vulnerable endpoint, bypassing the missing authorization check to retrieve sticky note data intended for administrators.
  5. Exfiltrate data: Review the returned sticky note content for sensitive information such as passwords, internal URLs, or administrative notes that can be leveraged for further attacks (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated Subscriber-level users making repeated or unusual requests to wp-admin AJAX endpoints (/wp-admin/admin-ajax.php) associated with the wb-sticky-notes plugin outside of normal dashboard usage patterns.
  • Logs: Unexpected access to sticky note data retrieval actions by non-administrator user accounts in WordPress debug or audit logs.
  • Network: Unusual HTTP GET/POST requests from low-privileged user sessions targeting plugin-specific endpoints or actions related to wb-sticky-notes.

Mitigation and workarounds

The vendor has released version 1.2.5 of the Sticky Notes for WP Dashboard plugin, which resolves this vulnerability. Site administrators should update the plugin to version 1.2.5 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. If an immediate update is not possible, consider deactivating the plugin until the patch can be applied, or use Patchstack's virtual patching feature to block exploitation without requiring a code update (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management