Логотип exploitDog
bind:CVE-2026-3906
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-3906

Количество 3

Количество 3

nvd логотип

CVE-2026-3906

18 дней назад

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-3906

18 дней назад

WordPress core is vulnerable to unauthorized access in versions 6.9 th ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6x83-fcf5-r65g

18 дней назад

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-3906

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
0%
Низкий
18 дней назад
debian логотип
CVE-2026-3906

WordPress core is vulnerable to unauthorized access in versions 6.9 th ...

CVSS3: 4.3
0%
Низкий
18 дней назад
github логотип
GHSA-6x83-fcf5-r65g

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS3: 4.3
0%
Низкий
18 дней назад

Уязвимостей на страницу