CVE-2026-62026: WordPress Dashboard Notes plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 9, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.
Affected Software
1 affected component
MIGHTYminnow Dashboard Notes<=1.0.3
Event History
Oct 9, 2026
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to induce a user to interact with a crafted request, as indicated by the required user interaction. No attacker privileges are required.
2
Which versions are affected?
Dashboard Notes versions through 1.0.3 are affected. The first fixed version is not provided.
3
What impact could successful exploitation have?
Successful exploitation may affect confidentiality, integrity, and availability at a low level. The vulnerability has scope changed, meaning the impact can extend beyond the vulnerable component's authorization scope.