cleantalk
Vulnerabilities and Security Researches

WP DSGVO Tools (GDPR), CVE-2026-11869

CVE, Research URL

CVE-2026-11869

Application

WP DSGVO Tools (GDPR)

Published on
Jul 09, 2026
Research Description
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Affected versions
max 3.1.40.
Status
vulnerable