CVE-2026-3906 | WordPress up to 6.9.1 Notes Feature create_item_permissions_check authorization (Nessus ID 302884 / WID-SEC-2026-0684)
A vulnerability was found in WordPress up to 6.9.1. It has been classified as problematic. This affects the function create_item_permissions_check of the component Notes Feature. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-3906. It is possible to initiate the attack remotely. There is no exploit available.