WordPress Plugin Vulnerabilities

GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF

Description

The plugin does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 3 days ago)
Added
2026-09-29 (about 10 days ago)
Last Updated
2026-09-29 (about 10 days ago)

Other