GHSA-25mp-f6qq-hg3fMediumCVSS 4.3

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

🔗 References (3)