PT-2024-16734 · WordPress · Wordpress Gdpr Plugin

István Márton

·

Published

2024-11-19

·

Updated

2024-11-22

·

CVE-2024-11069

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress GDPR plugin versions up to, and including, 2.0.2
Description The WordPress GDPR plugin is vulnerable to unauthorized loss of data due to a missing capability check on the WordPress GDPR Data Delete::check action function. This makes it possible for unauthenticated attackers to delete arbitrary users.
Recommendations Update to the latest version immediately to safeguard your site. As a temporary workaround, consider disabling the WordPress GDPR Data Delete::check action function until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-11069

Affected Products

Wordpress Gdpr Plugin