WordPress Plugin Vulnerabilities

The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam

Description

The plugin does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.

Proof of Concept

Affects Plugins

Fixed in 2.4.0

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 8 days ago)
Added
2026-07-27 (about 7 days ago)
Last Updated
2026-07-27 (about 7 days ago)

Other