CVE-2025-12071Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'funp_ajax_modify_notes' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary notes that do not belong to them.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-18: 3Technical Details · 2026-02-18: 302-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-12071 Insecure Direct Object Reference in WordPress Frontend User Notes Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-12071

    Post summary

    A brief mention of CVE-2025-12071 identifies an IDOR issue in a WordPress plugin, but no PoC, exploit, patch, or active exploitation details are provided.

    0001026
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-12071 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-12071 #CVE-2025-12071 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/XSguRyswCr

    Post summary

    A new WordPress CVE (CVE-2025-12071) is announced with a medium severity score of 4.3; no PoC, exploit, patch, or active exploitation details are provided.

    0000047
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-12071 The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'funp_ajax_modify_n… https://www.cve.org/CVERecord?id=CVE-2025-12071

    Post summary

    The Frontend User Notes plugin for WordPress is vulnerable to IDOR in all versions up to 2.1.0.

    00000184
    56.4K followersView on X

Explore more