Impact
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check when processing immediate data‑subject access requests. This flaw allows an attacker to supply a target user’s e‑mail address and trigger the full personal‑data export, exposing the name, postal address, phone number, e‑mail and comment content of that user. The vulnerability is a classic information disclosure (CWE‑200) compounded by an access‑control weakness (CWE‑284).
Affected Systems
All installations of WP DSGVO Tools (GDPR) WordPress plugin versions 3.1.39 and earlier are affected; any WordPress site that has not upgraded to 3.1.40 or later is vulnerable. The flaw exists across all deployments of the plugin through the public web surface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low, but not negligible. The vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker can exploit the flaw simply by making an HTTP request to the subject-access-request endpoint with only be able to reach the public web interface of the site.
OpenCVE Enrichment