PT-2026-27328 · WordPress · Wp Dsgvo Tools
Angus Girvan
·
Publicado
2026-03-24
·
Atualizado
2026-03-24
·
CVE-2026-4283
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP DSGVO Tools (GDPR) plugin for WordPress versions through 3.1.38
Description
The WP DSGVO Tools (GDPR) plugin for WordPress is susceptible to unauthorized account destruction. The
super-unsubscribe AJAX action allows unauthenticated users to bypass the email-confirmation process and immediately trigger irreversible account anonymization by submitting a victim's email address with the process now parameter set to 1. This results in password randomization, username/email overwriting, role stripping, comment anonymization, and the wiping of sensitive user metadata. The required nonce for the request is publicly available on any page containing the [unsubscribe form] shortcode. The vulnerable parameter is process now. The affected API endpoint is the super-unsubscribe AJAX action.Recommendations
Update to version 3.1.39 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Dsgvo Tools