PT-2026-27328 · WordPress · Wp Dsgvo Tools

Angus Girvan

·

Publicado

2026-03-24

·

Atualizado

2026-03-24

·

CVE-2026-4283

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP DSGVO Tools (GDPR) plugin for WordPress versions through 3.1.38
Description The WP DSGVO Tools (GDPR) plugin for WordPress is susceptible to unauthorized account destruction. The super-unsubscribe AJAX action allows unauthenticated users to bypass the email-confirmation process and immediately trigger irreversible account anonymization by submitting a victim's email address with the process now parameter set to 1. This results in password randomization, username/email overwriting, role stripping, comment anonymization, and the wiping of sensitive user metadata. The required nonce for the request is publicly available on any page containing the [unsubscribe form] shortcode. The vulnerable parameter is process now. The affected API endpoint is the super-unsubscribe AJAX action.
Recommendations Update to version 3.1.39 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4283

Produtos afetados

Wp Dsgvo Tools