Jeroensormani develops WordPress plugins, notably the Dashboard Notes plugin, with a narrow but targeted vulnerability footprint. The observed exposure centers on authorization and access-control weaknesses, reflecting the authentication and capability-gating demands of plugin-based WordPress extensions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jeroensormani over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7239HIGH The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users wit | May 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-43226MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects | Aug 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-7198MEDIUM The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete privat | Feb 27, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jeroensormani.
Media articles that mention a CVE ID that affects a product developed by Jeroensormani — matched by CVE ID, not by vendor name.