PT-2026-56699 · WordPress · Wp Dsgvo Tools
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP DSGVO Tools (GDPR) versions prior to 3.1.40
Description
The data subject access request feature fails to perform an authorization check on its immediate-processing path. This allows unauthenticated attackers to generate and download a full personal-data export of any user, customer, or commenter by providing their email address. The exported data includes names, postal addresses, phone numbers, emails, and comment content.
Recommendations
Update the plugin to version 3.1.40 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Dsgvo Tools