Missing Authorization Affecting wordpress package, versions <6.9.4+dfsg1-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.31% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-WORDPRESS-15702035
  • published20 Mar 2026
  • disclosed11 Mar 2026

Introduced: 11 Mar 2026

CVE-2026-3906  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade Debian:unstable wordpress to version 6.9.4+dfsg1-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream wordpress package and not the wordpress package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API create_item_permissions_check() method in the comments controller did not verify that the authenticated user has edit_post permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any status.

CVSS Base Scores

version 3.1