6.5
CVE-2026-14816
- EPSS 0.25%
- Veröffentlicht 04.08.2026 06:00:09
- Zuletzt bearbeitet 04.08.2026 15:16:25
- CVE-Watchlists
- Unerledigt
The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam
The GDPR Framework <= 2.3.0 - Missing Authorization
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.
Mögliche Gegenmaßnahme
The GDPR Framework By Data443: Update to version 2.4.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt
The GDPR Framework By Data443
Default Statusunaffected
Version
0
Version <
2.4.0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
The GDPR Framework By Data443
Version
*-2.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.163 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://wpscan.com/vulnerability/72af92a2-afe6-4e5a-9a1a-6f6e97bbcd85/
https://www.wordfence.com/threat-intel/vulnerabilities/id/9c025807-d4b7-405d-8e49-e2e6b3beba00