← Back to home
wid-sec-w-2026-0684  ·  Published 2026-03-10  ·  View on BSI CERT-Bund ↗

WordPress: Multiple Vulnerabilities

CVSS 4.3 MEDIUM

Risk Summary

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVEs (1)

Affected Vendors

Open Source

Affected Products (2)

Open Source · WordPress <6.9.2
Open Source · WordPress 6.9.2

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more