Dashboard Notepad
Dashboard Notepad has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Dashboard Notepad has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Que Thanh Tuan - Blue Rock. Dashboard Notepad is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
CVE-2025-57927Dashboard Notepad <= 1.42 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Dashboard Notepad
Author
Stephanie Leary
This dashboard widget provides a simple notepad. The widget settings allow you to choose which roles can edit the notes, and which roles can merely read them. Version 1.30 also adds support for custom roles and integrates with the Members plugin for role settings. You can display the contents of your notepad using a template tag and/or shortcode. The widget permissions apply to these tags as well: only users with permission to read the notes will see the notes on the front end. You can use div#dashboard-notes in your theme’s CSS file to style the notes. Translations Belorussian (be_BY) by FatCow. Bulgarian (bg_BG) by SiteGround. Dutch (nl_NL) by Axel Vanderhaeghen German (de_DE) by Guido Kerkewitz Italian (it_IT) translation by Francesco Bevivino Romanian (ro_RO) by Web Hosting Geeks (Web Geek Sciense Swedish (se_SV) by Rabatt Ukranian (uk_UA) by Michael Yunat Translations If you would like to send me a translation, please write to me through my contact page. Let me know which plugin you’ve translated and how you would like to be credited. I will write you back so you can attach the files in your reply.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C