sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total7
Critical1
High1
Medium5
Reset
Showing 1-7 of 7 records
Threat Entry Updated 2026-07-09

WP DSGVO Tools - Security Vulnerability (CVE-2026-11869)

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.

PLUGIN WP DSGVO Tools

CVE-2026-11869

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-06-22

WP DSGVO Tools - Broken Access Control (CVE-2026-10034)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitrary victim email address and trigger immediate SAR processing via the process_now and is_ajax parameters, receiving tokenized download links (zip_link, pdf_link) in the HTTP response that expose the victim's personal data — including WordPress account details, comment author names, email addresses,…

PLUGIN WP DSGVO Tools

CVE-2026-10034

MEDIUM CVSS 5.3 2026-06-19
Threat Entry Updated 2026-06-17

WP DSGVO Tools - Security Vulnerability (CVE-2026-4283)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomized, username/email overwritten, roles stripped, comments anonymized, sensitive usermeta wiped) by submitting the victim's email address with `process_now=1`. The nonce required for the request is publicly…

PLUGIN WP DSGVO Tools

CVE-2026-4283

CRITICAL CVSS 9.1 2026-03-24
Threat Entry Updated 2026-06-17

WP DSGVO Tools - Cross-Site Scripting (XSS) (CVE-2026-0914)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WP DSGVO Tools

CVE-2026-0914

MEDIUM CVSS 6.4 2026-01-23
Threat Entry Updated 2026-06-17

WP DSGVO Tools - Cross-Site Scripting (XSS) (CVE-2024-3201)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' shortcode in all versions up to, and including, 3.1.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WP DSGVO Tools

CVE-2024-3201

MEDIUM CVSS 6.4 2024-05-23
Threat Entry Updated 2026-06-17

Wp Dsgvo Tools - Cross-Site Scripting (XSS) (CVE-2021-4358)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Dsgvo Tools

CVE-2021-4358

HIGH CVSS 7.2 2023-06-07